Active Members akkiliON Posted November 6, 2014 Active Members Report Posted November 6, 2014 # URL Open Redirect on vBulletin# Risk: Low# CWE number: CWE-601# Version: 4.2.1# Date: 29/10/2014# Author: Felipe " Renzi " Gabriel# Contact: renzi@linuxmail.org# Tested on Windows 8 pro# Vulnerable File: go.php# Exploit: [+] http://host.com/go.php?url=http://site.com# PoC: [+] http://vb.bdr1.net/go.php?url=http://www.google.com Wait 30 seconds, and you will be redirect...# Note: Open redirect (CWE-601) allows phishing attack to be more effective. Redirection is commonly used within all web applications for various purposes.("Jason Lam" ~ Top 25 Series - Rank 23 - Open Redirect)# Reference: http://software-security.sans.org# Thank'sSource: vBulletin 4.2.1 Open Redirect ? Packet Storm Quote