CWE-601

Low likelihood

URL Redirection to Untrusted Site ('Open Redirect')

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

1,532 vulnerabilities with CWE-601
CVE-2008-2951 MEDIUM
Trac < 0.10.5 - Open Redirect via Search Script q Parameter
CVSS 6.1
CVE-2008-2052 MEDIUM
Bitrix Site Manager 6.5 - Open Redirect via redirect.php goto Parameter
CVSS 6.1
CVE-2005-10001 MEDIUM
Netegrity SiteMinder <4.5.1 - Open Redirect
CVSS 5.4
CVE-2005-4206 MEDIUM
Blackboard Academic Suite < 6.0.0.0 - URL Redirection via frameset.jsp url Parameter
CVSS 6.1
CVE-2005-1475
Opera Browser < 8.01 - Open Redirect via XMLHttpRequest
CVE-2005-0420
Microsoft Exchange Server - Open Redirect via OWA Login Page
CVE-2004-2260
Opera Browser <7.50 - Open Redirect
Details
Vulnerabilities 1,532
Exploit Likelihood Low