CVE-2011-0908

Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Target parameter to an unspecified component, a different vulnerability than CVE-2011-0526.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vanillaforums:vanilla:*:*:*:*:*:*:*:*
cpe:2.3:a:vanillaforums:vanilla:2.0.9:*:*:*:*:*:*:*
cpe:2.3:a:vanillaforums:vanilla:2.0.10:*:*:*:*:*:*:*
cpe:2.3:a:vanillaforums:vanilla:2.0.11:*:*:*:*:*:*:*
cpe:2.3:a:vanillaforums:vanilla:2.0.12:*:*:*:*:*:*:*
cpe:2.3:a:vanillaforums:vanilla:2.0.13:*:*:*:*:*:*:*
cpe:2.3:a:vanillaforums:vanilla:2.0.14:*:*:*:*:*:*:*
cpe:2.3:a:vanillaforums:vanilla:2.0.15:*:*:*:*:*:*:*
cpe:2.3:a:vanillaforums:vanilla:2.0.16:*:*:*:*:*:*:*
cpe:2.3:a:vanillaforums:vanilla:2.0.17:*:*:*:*:*:*:*
cpe:2.3:a:vanillaforums:vanilla:2.0.17.1:*:*:*:*:*:*:*
cpe:2.3:a:vanillaforums:vanilla:2.0.17.2:*:*:*:*:*:*:*
cpe:2.3:a:vanillaforums:vanilla:2.0.17.3:*:*:*:*:*:*:*
cpe:2.3:a:vanillaforums:vanilla:2.0.17.4:*:*:*:*:*:*:*

History

21 Nov 2024, 01:25

Type Values Removed Values Added
References () http://www.vanillaforums.org/discussion/comment/134729/#Comment_134729 - () http://www.vanillaforums.org/discussion/comment/134729/#Comment_134729 -

Information

Published : 2011-02-08 21:00

Updated : 2024-11-21 01:25


NVD link : CVE-2011-0908

Mitre link : CVE-2011-0908

CVE.ORG link : CVE-2011-0908


JSON object : View

Products Affected

vanillaforums

  • vanilla
CWE
CWE-20

Improper Input Validation