CVE-2015-1603
Summary
| CVE | CVE-2015-1603 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-02-19 15:59:17 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Adminsystems CMS before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php or (2) id parameter in a users_users action to asys/site/system.php. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adminsystems Cms Project | Adminsystems Cms | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version) -- Reflecting XSS, unrestricted file-upload and underlaying CSRF | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Full Disclosure: Reflecting XSS vulnerabitlies, unrestricted file upload and underlaying CSRF in Landsknecht Adminsystems CMS v. 4.0.1 (DEV, beta version) | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit |
| Landsknecht Adminsystems CMS 4.0.1 CSRF / XSS / File Upload ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| oss-security - CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version) -- Reflecting XSS, unrestricted file-upload and underlaying CSRF | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Exploit |
| oss-security - Re: CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version) -- Reflecting XSS, unrestricted file-upload and underlaying CSRF | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| XSS-vulnerabilities, unrestricted file-upload and underlaying CSRF-vulnerability in Adminsystems CMS v.4.0.1 (DEV) · Issue #1 · AschauerMarvin/adminsystems · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit |
| Release Adminsystems v4.0.2 · AschauerMarvin/adminsystems · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch |
| travel-free | af854a3a-2127-422b-91ae-364da2661108 | sroesemann.blogspot.de | Exploit |
| travel-free | af854a3a-2127-422b-91ae-364da2661108 | sroesemann.blogspot.de | Exploit |
| Landsknecht Adminsystems CMS Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.