Telaen CVE-2013-2621 Open Redirection Vulnerability
BID:60290
CVE-2013-2621 |Info
Telaen CVE-2013-2621 Open Redirection Vulnerability
| Bugtraq ID: | 60290 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2621 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2013 12:00AM |
| Updated: | Oct 10 2013 12:33AM |
| Credit: | Manuel Garcia Cardenas |
| Vulnerable: |
UebiMiau UebiMiau 2.7.10 UebiMiau UebiMiau 2.7.9 UebiMiau UebiMiau 2.7.2 |
| Not Vulnerable: | |
Discussion
Telaen CVE-2013-2621 Open Redirection Vulnerability
Telaen is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Versions prior to Telaen 1.3.1 are vulnerable.
Telaen is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Versions prior to Telaen 1.3.1 are vulnerable.
Exploit / POC
Telaen CVE-2013-2621 Open Redirection Vulnerability
An attacker can exploit this issue using a web browser.
The following example URI is available:
http://www.example.com/telaen/redir.php?http://www.malicious-site.com
An attacker can exploit this issue using a web browser.
The following example URI is available:
http://www.example.com/telaen/redir.php?http://www.malicious-site.com
Solution / Fix
Telaen CVE-2013-2621 Open Redirection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Telaen CVE-2013-2621 Open Redirection Vulnerability
References:
References: