Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2017-05-29 CVE-2017-9297 Open Redirect vulnerability in Hitachi Device Manager
Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to redirect users to arbitrary web sites.
network
low complexity
hitachi CWE-601
6.1
2017-05-29 CVE-2017-9296 Open Redirect vulnerability in Hitachi Device Manager
Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Tuning Manager before 8.5.2-00 allows remote attackers to redirect authenticated users to arbitrary web sites.
network
low complexity
hitachi CWE-601
6.1
2017-05-27 CVE-2017-7343 Open Redirect vulnerability in Fortinet Fortiportal
An open redirect vulnerability in Fortinet FortiPortal 4.0.0 and below allows attacker to execute unauthorized code or commands via the url parameter.
network
low complexity
fortinet CWE-601
6.1
2017-05-27 CVE-2017-3126 Open Redirect vulnerability in Fortinet Fortianalyzer Firmware and Fortimanager Firmware
An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthorized code or commands via the next parameter.
network
low complexity
fortinet CWE-601
6.1
2017-05-25 CVE-2015-3190 Open Redirect vulnerability in multiple products
With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the UAA logout link is susceptible to an open redirect which allows an attacker to insert malicious web page as a redirect parameter.
network
low complexity
pivotal-software cloudfoundry CWE-601
6.1
2017-05-22 CVE-2017-1159 Open Redirect vulnerability in IBM Business Process Manager
IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
5.4
2017-05-22 CVE-2017-2497 Open Redirect vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-601
6.1
2017-05-19 CVE-2015-5241 Open Redirect vulnerability in Apache Juddi
After logging into the portal, the logout jsp page redirects the browser back to the login page after.
network
low complexity
apache CWE-601
6.1
2017-05-18 CVE-2017-9062 Open Redirect vulnerability in multiple products
In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.
network
low complexity
wordpress debian CWE-601
8.6
2017-05-17 CVE-2015-4070 Open Redirect vulnerability in WOW NEW Media WOW Moodboard Lite 1.1.1
Open redirect vulnerability in the proxyimages function in wowproxy.php in the Wow Moodboard Lite plugin 1.1.1.1 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
network
low complexity
wow-new-media CWE-601
6.1