Record summary

CVE-2016-10368 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the back parameter to the /login URI.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMOpsview Monitor Pro - Open RedirectCVSS 6.1

Opsview Monitor Pro before 5.1.0.162300841, before 5.0.2.27475, before 4.6.4.162391051, and 4.5.x without a certain 2016 security patch contains an open redirect vulnerability. An attacker can redirect users to arbitrary web sites and conduct phishing attacks via the back parameter to the login URI.

Impact

An attacker can redirect users to malicious websites, leading to phishing attacks or the download of malware.

Remediation

Apply the latest patch or upgrade to a version that is not affected by the vulnerability.

WeaknessesCWE-601
Authors0x_Akoko
Template tagscve2016cveredirectopsviewauthenticatedvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:opsview:opsview:4.5.0:*:*:*:pro:*:*:*
Shodan: http.title:"opsview"
FOFA: title="opsview"
Google: intitle:"opsview"

Source: ProjectDiscovery

References

2