Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

fstec логотип

BDU:2019-01561

больше 7 лет назад

Уязвимость модуля аутентификации mod_auth_mellon сервера Apache HTTP Server, связанная с ошибками преобразования символов «\», позволяющая нарушителю перенаправить пользователя на вредоносный сайт

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-3877

больше 7 лет назад

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 5.8
EPSS: Низкий
redhat логотип

CVE-2019-3877

больше 7 лет назад

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-3877

больше 7 лет назад

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2019-3877

больше 7 лет назад

A vulnerability was found in mod_auth_mellon before v0.14.2. An open r ...

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-qr9h-f4fq-2h85

около 4 лет назад

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 6.1
EPSS: Низкий
oracle-oval логотип

ELSA-2019-3421

больше 6 лет назад

ELSA-2019-3421: mod_auth_mellon security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-0766

больше 7 лет назад

ELSA-2019-0766: mod_auth_mellon security and bug fix update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2019-01561

Уязвимость модуля аутентификации mod_auth_mellon сервера Apache HTTP Server, связанная с ошибками преобразования символов «\», позволяющая нарушителю перенаправить пользователя на вредоносный сайт

CVSS3: 6.1
2%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2019-3877

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 5.8
2%
Низкий
больше 7 лет назад
redhat логотип
CVE-2019-3877

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 6.1
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2019-3877

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 5.8
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2019-3877

A vulnerability was found in mod_auth_mellon before v0.14.2. An open r ...

CVSS3: 5.8
2%
Низкий
больше 7 лет назад
github логотип
GHSA-qr9h-f4fq-2h85

A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
oracle-oval логотип
ELSA-2019-3421

ELSA-2019-3421: mod_auth_mellon security, bug fix, and enhancement update (MODERATE)

2%
Низкий
больше 6 лет назад
oracle-oval логотип
ELSA-2019-0766

ELSA-2019-0766: mod_auth_mellon security and bug fix update (IMPORTANT)

больше 7 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.