CVE-2012-2270 Information

Description

Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

Reference

http://archives.neohapsis.com/archives/bugtraq/2012-04/0127.html http://osvdb.org/81211 http://owncloud.org/security/advisories/CVE-2012-2270/ http://packetstormsecurity.org/files/111956/ownCloud-3.0.0-Cross-Site-Scripting.html http://secunia.com/advisories/48850 http://www.openwall.com/lists/oss-security/2012/08/11/1 http://www.openwall.com/lists/oss-security/2012/09/02/2 http://www.securityfocus.com/bid/53145 http://www.tele-consulting.com/advisories/TC-SA-2012-01.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/75029 Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

Share on: