CVE-2014-9617
Netsweeper 3.0.6 - Open Redirection
Record summary
CVE-2014-9617 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMNetsweeper 3.0.6 - Open RedirectionCVSS 6.1
An open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to potential phishing attacks or the download of malware.
Remediation
Apply the latest security patches or updates provided by the vendor to fix the open redirection vulnerability.
Source: ProjectDiscovery