Plone CVE-2013-4195 Multiple Open Redirection Vulnerabilities
BID:61959
Info
Plone CVE-2013-4195 Multiple Open Redirection Vulnerabilities
| Bugtraq ID: | 61959 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4195 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2013 12:00AM |
| Updated: | Mar 19 2015 08:16AM |
| Credit: | Matthew Wilkes |
| Vulnerable: |
Plone Plone 4.1.3 Plone Plone 4.0.8 Plone Plone 4.0.7 Plone Plone 3.3.5 Plone Plone 3.3.4 Plone Plone 3.3.3 Plone Plone 3.3.2 Plone Plone 3.3.1 Plone Plone 3.2.3 Plone Plone 3.2.2 Plone Plone 3.1.6 Plone Plone 3.1.4 Plone Plone 3.0.5 Plone Plone 3.0.4 Plone Plone 3.0.3 Plone Plone 3.0.2 Plone Plone 3.0.1 Plone Plone 2.5.5 Plone Plone 2.5.4 Plone Plone 2.5.1 Plone Plone 2.1.2 Plone Plone 2.0.5 Plone Plone 2.0.4 Plone Plone 4.2a2 Plone Plone 4.2a1 Plone Plone 4.2 Plone Plone 4.1 Plone Plone 4.0.9 Plone Plone 4.0.6.1 Plone Plone 4.0.5 Plone Plone 4.0.4 Plone Plone 4.0.3 Plone Plone 4.0.2 Plone Plone 4.0.1 Plone Plone 4.0 Plone Plone 3.3.2 Plone Plone 3.3.1 Plone Plone 3.3 Plone Plone 3.3 Plone Plone 3.2.3 Plone Plone 3.2.2 Plone Plone 3.2.1 Plone Plone 3.2 Plone Plone 3.1.7 Plone Plone 3.1.6 Plone Plone 3.1.5.1 Plone Plone 3.1.3 Plone Plone 3.1.2 Plone Plone 3.1.1 Plone Plone 3.1 Plone Plone 3.0.6 Plone Plone 3.0 Plone Plone 2.5-beta1 Plone Plone 2.5 Plone Plone 2.1.3 Plone Plone 2.1.1 Plone Plone 2.1 Plone Plone 2.0.2 Plone Plone 2.0.1 Plone Plone 2.0 Plone Plone 1.0.6 Plone Plone 1.0.5 Plone Plone 1.0.4 Plone Plone 1.0.3 Plone Plone 1.0.2 Plone Plone 1.0.1 |
| Not Vulnerable: | |
Discussion
Plone CVE-2013-4195 Multiple Open Redirection Vulnerabilities
Plone is prone to multiple open-redirection vulnerabilities.
An attacker can leverage these issues by constructing a crafted URI to the affected script that redirects to a malicious website through the affected parameter. When an unsuspecting victim follows the URI, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Note: These issues were previously discussed in BID 61544 (Plone Multiple Remote Security Vulnerabilities) but has been given its own record to better document it.
Plone is prone to multiple open-redirection vulnerabilities.
An attacker can leverage these issues by constructing a crafted URI to the affected script that redirects to a malicious website through the affected parameter. When an unsuspecting victim follows the URI, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Note: These issues were previously discussed in BID 61544 (Plone Multiple Remote Security Vulnerabilities) but has been given its own record to better document it.
Exploit / POC
Plone CVE-2013-4195 Multiple Open Redirection Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to following a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting victim to following a malicious URI.
Solution / Fix
Plone CVE-2013-4195 Multiple Open Redirection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.