CVE-2008-5742

Published Dec 26, 2008

Last updated 7 years ago

Overview

Description
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the redirect parameter in a logoff action to modules/auth/index.php or (2) the url parameter to modules/linkmanager/redirect.php. NOTE: this was reported within an "HTTP Response Splitting" section in the original disclosure.
Source
cve@mitre.org
NVD status
Modified

Risk scores

CVSS 2.0

Type
Primary
Base score
4
Impact score
4.9
Exploitability score
4.9
Vector string
AV:N/AC:H/Au:N/C:N/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-59

Social media

Hype score
Not currently trending

Configurations