Red Hat Network Satellite Server URI Open Redirection Vulnerability
BID:49651
Info
Red Hat Network Satellite Server URI Open Redirection Vulnerability
| Bugtraq ID: | 49651 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1594 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2011 12:00AM |
| Updated: | Sep 15 2011 12:00AM |
| Credit: | Thomas Biege of the SuSE Security Team |
| Vulnerable: |
Red Hat Red Hat Network Satellite Server 5.4 |
| Not Vulnerable: | |
Discussion
Red Hat Network Satellite Server URI Open Redirection Vulnerability
Red Hat Network Satellite Server is prone to a URI open-redirection vulnerability because the application fails to properly sanitize user-supplied input.
Successful exploits may redirect a user to a potentially malicious site; this may aid in phishing attacks.
Red Hat Network Satellite Server is prone to a URI open-redirection vulnerability because the application fails to properly sanitize user-supplied input.
Successful exploits may redirect a user to a potentially malicious site; this may aid in phishing attacks.
Exploit / POC
Red Hat Network Satellite Server URI Open Redirection Vulnerability
An attacker can exploit this issue by injecting an external URI into the affected site.
An attacker can exploit this issue by injecting an external URI into the affected site.
Solution / Fix
Red Hat Network Satellite Server URI Open Redirection Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Red Hat Network Satellite Server URI Open Redirection Vulnerability
References:
References:
- Red Hat Homepage (Red Hat)
- Moderate: Red Hat Network Satellite server security and enhancement update (Thomas Biege)