Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.106720
Categoría:CISCO
Título:Cisco Integrated Management Controller Redirection Vulnerability
Resumen:A vulnerability in the web interface of Cisco Integrated Management;Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web;page.
Descripción:Summary:
A vulnerability in the web interface of Cisco Integrated Management
Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web
page.

Vulnerability Insight:
The vulnerability is due to improper input validation of parameters in
HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected
system, which could cause the web interface of the affected software to redirect the request to a malicious URL.

Vulnerability Impact:
This vulnerability is known as an open redirect attack, which is used in
phishing attacks to get users to visit malicious sites without their knowledge.

Solution:
See vendor advisory

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-6604
BugTraq ID: 97457
http://www.securityfocus.com/bid/97457
http://www.securitytracker.com/id/1038186
CopyrightCopyright (C) 2017 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.