CVE-2011-4553
Published Dec 6, 2011
Last updated 13 years ago
Overview
- Description
- Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the return_to parameter, and allow (2) remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via crafted characters in the domain name of a subdomain.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.8
- Impact score
- 4.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:oneclickorgs:one_click_orgs:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "986482E2-0875-41FD-B10F-1D415229722E", "versionEndIncluding": "1.2.2" }, { "criteria": "cpe:2.3:a:oneclickorgs:one_click_orgs:1.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E19D160-676C-4D93-8224-DD3BA7296A56" }, { "criteria": "cpe:2.3:a:oneclickorgs:one_click_orgs:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0551C219-6CD6-4DBB-B36F-54B750EDA9F6" }, { "criteria": "cpe:2.3:a:oneclickorgs:one_click_orgs:1.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04E09162-B070-441F-BE2D-EF2C5F515339" }, { "criteria": "cpe:2.3:a:oneclickorgs:one_click_orgs:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20A2140E-685F-41E7-AEC4-82DEBC2B3B60" }, { "criteria": "cpe:2.3:a:oneclickorgs:one_click_orgs:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23D9A2D4-CC43-453E-A3A6-17DD21988617" }, { "criteria": "cpe:2.3:a:oneclickorgs:one_click_orgs:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "43103D6D-C861-409B-BC58-036B735F5C4C" } ], "operator": "OR" } ] } ]