Vulnerabilities (CVE)

Filtered by CWE-601
Total 999 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-7473 1 Soconnect 2 Sowifi Hotspot, Sowifi Hotspot Firmware 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
Open redirect vulnerability in the SO Connect SO WIFI hotspot web interface, prior to version 140, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL.
CVE-2017-0364 2 Debian, Mediawiki 2 Debian Linux, Mediawiki 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.
CVE-2018-7674 1 Netiq 1 Identity Manager 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
CVE-2017-18262 1 Blackboard 1 Blackboard Learn 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibboleth-BBLEARN/execute/shibbolethLogin?returnUrl= URI.
CVE-2018-3743 1 Hekto Project 1 Hekto 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.
CVE-2018-10101 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
CVE-2018-1355 1 Fortinet 2 Fortianalyzer, Fortimanager 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.
CVE-2018-11041 1 Pivotal Software 2 Cloud Foundry Uaa, Cloud Foundry Uaa-release 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote attacker can craft a malicious link that, when clicked, will redirect users to arbitrary websites after a successful login attempt.
CVE-2017-5389 1 Mozilla 1 Firefox 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.
CVE-2017-2166 1 Groupsession 1 Groupsession 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVE-2018-1220 1 Emc 1 Rsa Archer 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
EMC RSA Archer, versions prior to 6.2.0.8, contains a redirect vulnerability in the QuickLinks feature. A remote attacker may potentially exploit this vulnerability to redirect genuine users to phishing websites with the intent of obtaining sensitive information from the users.
CVE-2017-14802 1 Netiq 1 Access Manager 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.
CVE-2017-1748 1 Ibm 1 Connections 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 135521.
CVE-2018-1248 1 Rsa 1 Authentication Manager 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could allow a remote attacker to potentially poison HTTP cache and subsequently redirect users to arbitrary web domains.
CVE-2018-6324 1 F-secure 1 Radar 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
F-Secure Radar (on-premises) before 2018-02-15 has an Unvalidated Redirect via the ReturnUrl parameter that triggers upon a user login.
CVE-2017-0363 2 Debian, Mediawiki 2 Debian Linux, Mediawiki 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
CVE-2018-0097 1 Cisco 1 Prime Infrastructure 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect. The vulnerability is due to improper input validation of the parameters in the HTTP request. An attacker could exploit this vulnerability by crafting an HTTP request that could cause the web application to redirect the request to a specific malicious URL. This vulnerability is known as an open redirect attack and is used in phishing attacks to get users to visit malicious sites without their knowledge. Cisco Bug IDs: CSCve37646.
CVE-2018-10678 1 Mybb 1 Mybb 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
CVE-2017-16224 1 St Project 1 St 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to //nodesecurity.org/%2e%2e which most browsers treat as a proper redirect as // is translated into the current schema being used. Mitigating factor: In order for this to work, st must be serving from the root of a server (/) rather than the typical sub directory (/static/) and the redirect URL will end with some form of URL encoded .. ("%2e%2e", "%2e.", ".%2e").
CVE-2018-6520 1 Simplesamlphp 1 Simplesamlphp 2024-02-28 5.8 MEDIUM 6.1 MEDIUM
SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.