Vulnerabilities > CVE-2014-6255 - Open Redirection vulnerability in Zenoss
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
NONE Summary
Open redirect vulnerability in the login form in Zenoss Core before 4.2.5 SP161 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the came_from parameter, aka ZEN-11998. <a href="http://cwe.mitre.org/data/definitions/601.html">CWE-601: URL Redirection to Untrusted Site ('Open Redirect')</a>
Vulnerable Configurations
Statements
contributor | Zenoss |
lastmodified | 2016-03-21 |
organization | Zenoss |
statement | Addressed in versions 5.0, 4.2.5.SP167, and 4.2.4.SP555 |