CVE-2011-5252
medium · 5.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the ReturnUrl parameter.
5.8
CVSS
11.9%
EPSS (exploit prob.)
96th
EPSS percentile
2013-01-12
Published
AV:N/AC:M/Au:N/C:P/I:P/A:N
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| orchardproject | orchard | 1.0 |
| orchardproject | orchard | 1.0.20 |
| orchardproject | orchard | 1.1 |
| orchardproject | orchard | 1.1.30 |
| orchardproject | orchard | 1.2 |
| orchardproject | orchard | 1.2.41 |
| orchardproject | orchard | 1.3 |
| orchardproject | orchard | 1.3.9 |
| orchardproject | orchard | 1.3.10 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2012-01/0023.html
- http://orchard.codeplex.com/discussions/283667
- http://secunia.com/advisories/47398
- http://www.mavitunasecurity.com/open-redirection-vulnerability-in-orchard/
- http://www.securityfocus.com/bid/51260
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72110
- http://archives.neohapsis.com/archives/bugtraq/2012-01/0023.html
- http://orchard.codeplex.com/discussions/283667
- http://secunia.com/advisories/47398
- http://www.mavitunasecurity.com/open-redirection-vulnerability-in-orchard/
- http://www.securityfocus.com/bid/51260
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72110
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-5252