Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2019-11-04 CVE-2010-3669 Open Redirect vulnerability in Typo3
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.
network
low complexity
typo3 CWE-601
5.4
2019-11-01 CVE-2010-3661 Open Redirect vulnerability in Typo3
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.
network
low complexity
typo3 CWE-601
6.1
2019-10-02 CVE-2019-4538 Open Redirect vulnerability in IBM Security Directory Server 6.4.0
IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
8.2
2019-10-01 CVE-2019-15041 Open Redirect vulnerability in Jetbrains Youtrack
JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.
network
low complexity
jetbrains CWE-601
6.1
2019-09-25 CVE-2019-10098 Open Redirect vulnerability in Apache Http Server
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.
network
low complexity
apache CWE-601
6.1
2019-09-20 CVE-2019-14912 Open Redirect vulnerability in Prise Adas 1.7.0
An issue was discovered in PRiSE adAS 1.7.0.
network
low complexity
prise CWE-601
6.1
2019-09-17 CVE-2019-16393 Open Redirect vulnerability in multiple products
SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.
network
low complexity
spip debian canonical CWE-601
6.1
2019-09-12 CVE-2019-6009 Open Redirect vulnerability in Ss-Proj Shirasagi
Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
low complexity
ss-proj CWE-601
6.1
2019-09-12 CVE-2019-6004 Open Redirect vulnerability in Fujixerox products
Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
low complexity
fujixerox CWE-601
6.1
2019-09-12 CVE-2019-5978 Open Redirect vulnerability in Cybozu Garoon
Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the application 'Scheduler'.
network
low complexity
cybozu CWE-601
6.1