CVE-2012-4032

NUCLEI

WebsitePanel < 1.2.2.1 - Open Redirect via ReturnUrl Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-4032. PoCs published by Anastasios Monachos. A Nuclei detection template is also available.

AI-analyzed exploit summary The exploit describes a URI-redirection vulnerability in WebsitePanel due to improper input sanitization. Attackers can craft malicious URLs to redirect users to arbitrary domains, aiding in phishing attacks.

Description

Open redirect vulnerability in the login page in WebsitePanel before 1.2.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in ReturnUrl to Default.aspx.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Anastasios Monachos · textwebappsasp
https://www.exploit-db.com/exploits/37488

The exploit describes a URI-redirection vulnerability in WebsitePanel due to improper input sanitization. Attackers can craft malicious URLs to redirect users to arbitrary domains, aiding in phishing attacks.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: WebsitePanel versions prior to 1.2.2.1
No auth needed
Prerequisites: Access to craft a malicious URL with the vulnerable parameter
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

WebsitePanel before v1.2.2.1 - Open Redirect
MEDIUMby ctflearner
Shodan: title:"WebsitePanel" html:"login" || http.title:"websitepanel" html:"login"
FOFA: title="websitepanel" html:"login"

References (6)

Core 6
Core References
Various Sources x_refsource_confirm
http://websitepanel.codeplex.com/workitem/224
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/83689
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/54346
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49813
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/76803

Scores

EPSS 0.0601
EPSS Percentile 90.9%

Details

CWE
CWE-20
Status published
Products (7)
websitepanel/websitepanel 1.0.0
websitepanel/websitepanel 1.0.1
websitepanel/websitepanel 1.0.2
websitepanel/websitepanel 1.1.0
websitepanel/websitepanel 1.1.2
websitepanel/websitepanel 1.2.0
websitepanel/websitepanel < 1.2.1
Published Jul 17, 2012
Tracked Since Feb 18, 2026