Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) pidvesa cookie to u5admin/pidvesa.php or (2) uri parameter to u5admin/meta2.php.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a custom Metasploit exploit module (achat_bof.rb) targeting CVE-2015-1578, a buffer overflow in Achat 0.150 beta7 on Windows. The exploit is delivered via a crafted UDP packet to the Achat service (default port 9256). The module is designed to be a clean example of Metasploit exploit development, demonstrating dynamic shellcode generation using msfvenom with Unicode encoding to bypass bad characters. The payload is a reverse shell (windows/shell_reverse_tcp) that connects back to the attacker's specified LHOST:LPORT. The install.sh script automates installation of the module into the user's Metasploit directory. The README provides detailed usage instructions, including required options (RHOSTS, LHOST, LPORT, RPORT). The exploit is operational and provides remote code execution if successful. No hardcoded IPs or domains are present; all endpoints are user-supplied at runtime.
This repository is a proof-of-concept exploit for CVE-2015-1578, a buffer overflow vulnerability in Achat 0.150 beta7 on Windows. The exploit is implemented in Python (chatter.py) and demonstrates remote code execution by sending a specially crafted UDP packet to the target Achat server. The exploit dynamically generates a Unicode-encoded reverse shell payload using msfvenom, with user-supplied LHOST and LPORT parameters, and launches a listener using Netcat (via rlwrap). The main script (chatter.py) handles argument parsing, payload generation, listener setup, and payload delivery over UDP. The kallisti.py file is a decorative script that prints colored ASCII art and is invoked at the start of the exploit for visual effect. The README.md provides detailed usage instructions, dependencies, and an overview of the exploit's purpose. No hardcoded IPs or domains are present; all network endpoints are supplied by the user at runtime. The exploit is a clean, minimal, and educational example of buffer overflow exploitation and reverse shell delivery.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.