{"api_version":"1","generated_at":"2026-07-23T06:59:10+00:00","cve":"CVE-2015-1603","urls":{"html":"https://cve.report/CVE-2015-1603","api":"https://cve.report/api/cve/CVE-2015-1603.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-1603","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-1603"},"summary":{"title":"CVE-2015-1603","description":"Multiple cross-site scripting (XSS) vulnerabilities in Adminsystems CMS before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php or (2) id parameter in a users_users action to asys/site/system.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-02-19 15:59:17","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2015/02/14/1","name":"http://www.openwall.com/lists/oss-security/2015/02/14/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Re: CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version) -- Reflecting XSS, unrestricted file-upload and underlaying CSRF","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2015/Feb/50","name":"http://seclists.org/fulldisclosure/2015/Feb/50","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Full Disclosure: Reflecting XSS vulnerabitlies, unrestricted file upload and underlaying CSRF in Landsknecht Adminsystems CMS v. 4.0.1 (DEV, beta version)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/130394/Landsknecht-Adminsystems-CMS-4.0.1-CSRF-XSS-File-Upload.html","name":"http://packetstormsecurity.com/files/130394/Landsknecht-Adminsystems-CMS-4.0.1-CSRF-XSS-File-Upload.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Landsknecht Adminsystems CMS 4.0.1 CSRF / XSS / File Upload ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2015/02/13/11","name":"http://www.openwall.com/lists/oss-security/2015/02/13/11","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"oss-security - CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version)\n -- Reflecting XSS, unrestricted file-upload and underlaying CSRF","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2015/02/14/5","name":"http://www.openwall.com/lists/oss-security/2015/02/14/5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Re: CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version) -- Reflecting XSS, unrestricted file-upload and underlaying CSRF","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/kneecht/adminsystems/issues/1","name":"https://github.com/kneecht/adminsystems/issues/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"XSS-vulnerabilities, unrestricted file-upload and underlaying CSRF-vulnerability in Adminsystems CMS v.4.0.1 (DEV) · Issue #1 · AschauerMarvin/adminsystems · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/kneecht/adminsystems/releases/tag/4.0.2","name":"https://github.com/kneecht/adminsystems/releases/tag/4.0.2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Release Adminsystems v4.0.2 · AschauerMarvin/adminsystems · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sroesemann.blogspot.de/2015/02/report-for-advisory-sroeadv-2015-14.html","name":"http://sroesemann.blogspot.de/2015/02/report-for-advisory-sroeadv-2015-14.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"travel-free","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://sroesemann.blogspot.de/2015/01/sroeadv-2015-14.html","name":"http://sroesemann.blogspot.de/2015/01/sroeadv-2015-14.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"travel-free","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/72605","name":"http://www.securityfocus.com/bid/72605","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Landsknecht Adminsystems CMS Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-1603","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1603","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"1603","vulnerable":"1","versionEndIncluding":"4.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adminsystems_cms_project","cpe5":"adminsystems_cms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T04:47:17.470Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20150213 Reflecting XSS vulnerabitlies, unrestricted file upload and underlaying CSRF in Landsknecht Adminsystems CMS v. 4.0.1 (DEV, beta version)","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2015/Feb/50"},{"name":"72605","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/72605"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://sroesemann.blogspot.de/2015/02/report-for-advisory-sroeadv-2015-14.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/130394/Landsknecht-Adminsystems-CMS-4.0.1-CSRF-XSS-File-Upload.html"},{"name":"[oss-security] 20150214 Re: CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version) -- Reflecting XSS, unrestricted file-upload and underlaying CSRF","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2015/02/14/5"},{"name":"[oss-security] 20150213 CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version)  -- Reflecting XSS, unrestricted file-upload and underlaying CSRF","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2015/02/13/11"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://sroesemann.blogspot.de/2015/01/sroeadv-2015-14.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/kneecht/adminsystems/releases/tag/4.0.2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/kneecht/adminsystems/issues/1"},{"name":"[oss-security] 20150213 Re: CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version) -- Reflecting XSS, unrestricted file-upload and underlaying CSRF","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2015/02/14/1"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-02-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Adminsystems CMS before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php or (2) id parameter in a users_users action to asys/site/system.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-02-19T13:57:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20150213 Reflecting XSS vulnerabitlies, unrestricted file upload and underlaying CSRF in Landsknecht Adminsystems CMS v. 4.0.1 (DEV, beta version)","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2015/Feb/50"},{"name":"72605","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/72605"},{"tags":["x_refsource_MISC"],"url":"http://sroesemann.blogspot.de/2015/02/report-for-advisory-sroeadv-2015-14.html"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/130394/Landsknecht-Adminsystems-CMS-4.0.1-CSRF-XSS-File-Upload.html"},{"name":"[oss-security] 20150214 Re: CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version) -- Reflecting XSS, unrestricted file-upload and underlaying CSRF","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2015/02/14/5"},{"name":"[oss-security] 20150213 CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version)  -- Reflecting XSS, unrestricted file-upload and underlaying CSRF","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2015/02/13/11"},{"tags":["x_refsource_MISC"],"url":"http://sroesemann.blogspot.de/2015/01/sroeadv-2015-14.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/kneecht/adminsystems/releases/tag/4.0.2"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/kneecht/adminsystems/issues/1"},{"name":"[oss-security] 20150213 Re: CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version) -- Reflecting XSS, unrestricted file-upload and underlaying CSRF","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2015/02/14/1"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-1603","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Adminsystems CMS before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php or (2) id parameter in a users_users action to asys/site/system.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20150213 Reflecting XSS vulnerabitlies, unrestricted file upload and underlaying CSRF in Landsknecht Adminsystems CMS v. 4.0.1 (DEV, beta version)","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2015/Feb/50"},{"name":"72605","refsource":"BID","url":"http://www.securityfocus.com/bid/72605"},{"name":"http://sroesemann.blogspot.de/2015/02/report-for-advisory-sroeadv-2015-14.html","refsource":"MISC","url":"http://sroesemann.blogspot.de/2015/02/report-for-advisory-sroeadv-2015-14.html"},{"name":"http://packetstormsecurity.com/files/130394/Landsknecht-Adminsystems-CMS-4.0.1-CSRF-XSS-File-Upload.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/130394/Landsknecht-Adminsystems-CMS-4.0.1-CSRF-XSS-File-Upload.html"},{"name":"[oss-security] 20150214 Re: CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version) -- Reflecting XSS, unrestricted file-upload and underlaying CSRF","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2015/02/14/5"},{"name":"[oss-security] 20150213 CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version)  -- Reflecting XSS, unrestricted file-upload and underlaying CSRF","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2015/02/13/11"},{"name":"http://sroesemann.blogspot.de/2015/01/sroeadv-2015-14.html","refsource":"MISC","url":"http://sroesemann.blogspot.de/2015/01/sroeadv-2015-14.html"},{"name":"https://github.com/kneecht/adminsystems/releases/tag/4.0.2","refsource":"CONFIRM","url":"https://github.com/kneecht/adminsystems/releases/tag/4.0.2"},{"name":"https://github.com/kneecht/adminsystems/issues/1","refsource":"CONFIRM","url":"https://github.com/kneecht/adminsystems/issues/1"},{"name":"[oss-security] 20150213 Re: CVE-Request -- Landsknecht Adminsystems v.4.0.1 (DEV, beta version) -- Reflecting XSS, unrestricted file-upload and underlaying CSRF","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2015/02/14/1"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2015-1603","datePublished":"2015-02-19T15:00:00.000Z","dateReserved":"2015-02-14T00:00:00.000Z","dateUpdated":"2024-08-06T04:47:17.470Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-02-19 15:59:17","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adminsystems_cms_project:adminsystems_cms:*:*:*:*:*:*:*:*","versionEndIncluding":"4.0.0","matchCriteriaId":"D5257182-FB6E-4718-A6A2-860D780BC5B3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"1603","Ordinal":"1","Title":"CVE-2015-1603","CVE":"CVE-2015-1603","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"1603","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Adminsystems CMS before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php or (2) id parameter in a users_users action to asys/site/system.php.","Type":"Description","Title":"CVE-2015-1603"},{"CveYear":"2015","CveId":"1603","Ordinal":"2","NoteData":"2015-02-19","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"1603","Ordinal":"3","NoteData":"2015-02-19","Type":"Other","Title":"Modified"}]}}}