Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2017-02-03 CVE-2017-3810 Open Redirect vulnerability in Cisco Prime Service Catalog 10.0(R2)Base
A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system.
network
low complexity
cisco CWE-601
5.4
2017-02-01 CVE-2016-8961 Open Redirect vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
6.1
2017-02-01 CVE-2016-6020 Open Redirect vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
6.1
2017-01-26 CVE-2016-6908 Open Redirect vulnerability in Opera Browser 37.0.2192.105088
Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to mishandling of several unicode characters such as U+FE70, U+0622, U+0623 etc and how they are rendered combined with (first strong character) such as an IP address or alphabet could lead to a spoofed URL.
network
low complexity
opera CWE-601
6.1
2017-01-26 CVE-2017-3799 Open Redirect vulnerability in Cisco Webex Meeting Center Wbs28Base
A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection.
network
low complexity
cisco CWE-601
5.4
2017-01-14 CVE-2017-5474 Open Redirect vulnerability in S9Y Serendipity
Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.
network
low complexity
s9y CWE-601
6.1
2017-01-12 CVE-2016-5715 Open Redirect vulnerability in Puppet Enterprise
Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the redirect parameter.
network
low complexity
puppet CWE-601
6.1
2017-01-12 CVE-2015-6501 Open Redirect vulnerability in Puppet Enterprise
Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the string parameter.
network
low complexity
puppet CWE-601
6.1
2016-12-16 CVE-2016-6657 Open Redirect vulnerability in Pivotal Software products
An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components.
network
low complexity
pivotal-software CWE-601
7.4
2016-12-15 CVE-2016-3174 Open Redirect vulnerability in Open-Xchange Appsuite
An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27.
network
low complexity
open-xchange CWE-601
7.4