id: CVE-2014-9180 info: name: Eleanor CMS - Open Redirect author: Shankar Acharya severity: medium description: | Open redirect vulnerability in go.php in Eleanor CMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the QUERY_STRING. remediation: | Update to the latest version of Eleanor CMS to fix the open redirect vulnerability. reference: - https://packetstormsecurity.com/files/129087/Eleanor-CMS-Open-Redirect.html - https://nvd.nist.gov/vuln/detail/CVE-2014-9180 classification: cvss-metrics: CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N cvss-score: 5 cve-id: CVE-2014-9180 cwe-id: CWE-601 epss-score: 0.00248 epss-percentile: 0.62551 cpe: cpe:2.3:a:eleanor-cms:eleanor_cms:-:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: eleanor-cms product: eleanor_cms shodan-query: html:"eleanor" tags: packetstorm,cve,cve2014,eleanor,cms,redirect http: - method: GET path: - "{{BaseURL}}/go.php?http://interact.sh" matchers: - type: regex part: header regex: - '(?m)^(?:Location\s*?:\s*?)(?:http?://|//)(?:[a-zA-Z0-9\-_\.@]*)interact\.sh.*$' # digest: 4a0a0047304502206347237dc9408ed3c3886a02e4a9958d204ad2c29813910579ba2a08f2b4efed02210092c0cae63b0947e58e7d6e5667ca6241addef161c161f04f8f014ba5c4fba949:922c64590222798bb761d5b6d8e72950