Описание
Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.
Ссылки
- Broken Link
- Broken LinkVendor Advisory
- Release Notes
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Mailing List
- Mailing List
- Broken Link
- Broken LinkVendor Advisory
- Release Notes
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Mailing List
- Mailing List
Уязвимые конфигурации
Конфигурация 1Версия до 0.10.5 (исключая)
cpe:2.3:a:edgewall:trac:*:*:*:*:*:*:*:*
Конфигурация 2
Одно из
cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:*
EPSS
Процентиль: 69%
0.006
Низкий
6.1 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-601
Связанные уязвимости
CVSS3: 6.1
ubuntu
больше 17 лет назад
Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.
CVSS3: 6.1
debian
больше 17 лет назад
Open redirect vulnerability in the search script in Trac before 0.10.5 ...
EPSS
Процентиль: 69%
0.006
Низкий
6.1 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-601