Vulnerabilities > CVE-2014-8754 - Unspecified vulnerability in Ad-Manager Project Ad-Manager 1.1.2

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE

Summary

Open redirect vulnerability in track-click.php in the Ad-Manager plugin 1.1.2 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the out parameter. <a href="http://cwe.mitre.org/data/definitions/601.html" target="_blank">CWE-601: URL Redirection to Untrusted Site ('Open Redirect')</a>

Vulnerable Configurations

Part Description Count
Application
Ad-Manager_Project
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/129290/wpadmanager-redirect.txt
idPACKETSTORM:129290
last seen2016-12-05
published2014-11-27
reporterJing Wang
sourcehttps://packetstormsecurity.com/files/129290/WordPress-Ad-Manager-1.1.2-Open-Redirect.html
titleWordPress Ad-Manager 1.1.2 Open Redirect