CVE-2012-4982
Forescout CounterACT - 'a' Open Redirection
Record summary
CVE-2012-4982 has a selected CVSS score of 5.8; EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the a parameter.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBForescout CounterACT - 'a' Open RedirectionExploitDB exploitby Joseph SheridanNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMForescout CounterACT 6.3.4.1 - Open RedirectCVSS 5.8
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the 'a' parameter.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the download of malware.
Remediation
Apply the latest security patches or upgrade to a newer version of Forescout CounterACT to fix the open redirect vulnerability.
Source: ProjectDiscovery