Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2017-05-03 CVE-2016-10368 Open Redirect vulnerability in Opsview
Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the back parameter to the /login URI.
network
low complexity
opsview CWE-601
6.1
2017-05-03 CVE-2015-9058 Open Redirect vulnerability in Proxmox Mail Gateway
Open redirect vulnerability in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter.
network
low complexity
proxmox CWE-601
6.1
2017-04-24 CVE-2017-3528 Open Redirect vulnerability in Oracle Applications Framework
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, etc.)).
network
low complexity
oracle CWE-601
5.4
2017-04-21 CVE-2016-4075 Open Redirect vulnerability in Opera Browser and Opera Mini
Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.
network
low complexity
opera CWE-601
6.1
2017-04-20 CVE-2016-1213 Open Redirect vulnerability in Cybozu Garoon
The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites.
network
low complexity
cybozu CWE-601
6.1
2017-04-17 CVE-2016-0228 Open Redirect vulnerability in IBM Marketing Platform 10.0
IBM Marketing Platform 10.0 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in various scripts.
network
low complexity
ibm CWE-601
5.4
2017-04-10 CVE-2016-4334 Open Redirect vulnerability in Jivesoftware Jive
Jive before 2016.3.1 has an open redirect from the external-link.jspa page.
network
low complexity
jivesoftware CWE-601
6.1
2017-04-07 CVE-2017-6604 Open Redirect vulnerability in Cisco Unified Computing System 2.2(8B)/3.0(1C)/3.1(2C)B
A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
network
low complexity
cisco CWE-601
6.1
2017-04-07 CVE-2017-3889 Open Redirect vulnerability in Cisco Registered Envelope Service 5.1.0015
A vulnerability in the web interface of the Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to redirect a user to a undesired web page, aka an Open Redirect.
network
low complexity
cisco CWE-601
6.1
2017-04-04 CVE-2017-7234 Open Redirect vulnerability in Djangoproject Django
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.
network
low complexity
djangoproject CWE-601
6.1