[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-1000671 -- sympa

ID: oval:org.secpod.oval:def:2000087Date: (C)2019-04-22   (M)2021-06-02
Class: VULNERABILITYFamily: unix




sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be exploitable via Victim"s browser must follow a URL supplied by the attacker. This vulnerability appears to have been fixed in none available.

Platform:
Debian 8.x
Debian 9.x
Product:
sympa
Reference:
CVE-2018-1000671
CVE    1
CVE-2018-1000671
CPE    4
cpe:/a:sympa:sympa
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/o:debian:debian_linux:8.0
...

© SecPod Technologies