6.1

CVE-2016-10368

Exploit
Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the back parameter to the /login URI.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpsviewOpsview Version4.5.0 SwEditionpro
OpsviewOpsview Version4.6.4 SwEditionpro
OpsviewOpsview Version5.0.2 SwEditionpro
OpsviewOpsview Version5.1.0 SwEditionpro
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.18% 0.8
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-016/?fid=8341
Third Party Advisory
Exploit