.. / CVE-2015-7823

Exploit for Kentico CMS 8.2 - Open Redirect (CVE-2015-7823)

Description:

Kentico CMS 8.2 contains an open redirect vulnerability via GetDocLink.ashx with link variable. An attacker can construct a URL within the application that causes a redirection to an arbitrary external domain.

Nuclei Template

View the template here CVE-2015-7823.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2015/CVE-2015-7823.yaml
Copy

References:

http://packetstormsecurity.com/files/133981/Kentico-CMS-8.2-Cross-Site-Scripting-Open-Redirect.html
https://github.com/ARPSyndicate/kenzer-templates
https://packetstormsecurity.com/files/133981/Kentico-CMS-8.2-Cross-Site-Scripting-Open-Redirect.html
https://nvd.nist.gov/vuln/detail/CVE-2015-7823