High severity7.2NVD Advisory· Published Apr 24, 2017· Updated May 13, 2026
CVE-2015-7570
CVE-2015-7570
Description
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open ports via the dbhost parameter to libs/org/adodb_lite/tests/test_adodb_lite.php, libs/org/adodb_lite/tests/test_datadictionary.php, or libs/org/adodb_lite/tests/test_adodb_lite_sessions.php.
Affected products
1- cpe:2.3:a:yeager:yeager_cms:1.2.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- seclists.org/fulldisclosure/2016/Feb/44nvdMailing ListPatchThird Party Advisory
- packetstormsecurity.com/files/135716/Yeager-CMS-1.2.1-File-Upload-SQL-Injection-XSS-SSRF.htmlnvdExploitPatchThird Party Advisory
- www.exploit-db.com/exploits/39436/nvdExploitPatchThird Party AdvisoryVDB Entry
- www.securityfocus.com/archive/1/537493/100/0/threadednvd
News mentions
0No linked articles in our index yet.