CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,682 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 2 of 34
- CVE-2016-1000110MEDIUMCVSS 6.1EG 6.12019-11-27
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
- CVE-2016-10315MEDIUMCVSS 6.1EG 6.12017-04-03
Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct Open Redirect attacks via the submit-…
- CVE-2016-10316MEDIUMCVSS 6.1EG 6.12017-04-03
Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct Open Redirect attacks via the return-…
- CVE-2016-10365MEDIUMCVSS 6.1EG 6.12017-06-16
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.
- CVE-2016-10368MEDIUMCVSS 6.1EG 6.12017-05-03
Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch) allows remote attackers to redirect users to arbitrary web sites…
- CVE-2016-10742MEDIUMCVSS 6.1EG 6.12019-02-17
Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.
- CVE-2016-10769MEDIUMCVSS 6.1EG 6.12019-08-05
cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).
- CVE-2016-1213MEDIUMCVSS 6.1EG 6.12017-04-20
The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites.
- CVE-2016-15030MEDIUMCVSS 3.5EG 6.12023-03-25
A vulnerability classified as problematic has been found in Arno0x TwoFactorAuth. This affects an unknown part of the file login/login.php. The manipulation of the argument from leads to open redirect. It is possible to initiate the attack…
- CVE-2016-3040MEDIUMCVSS 6.8EG 6.82016-09-26
IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, allows remote authenticated users to redirect users to arbitrary web sites and conduct phis…
- CVE-2016-3047MEDIUMCVSS 6.8EG 6.82016-12-01
Open redirect vulnerability in IBM FileNet Workplace 4.0.2 through 4.0.2.14 IF001 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2016-3174HIGHCVSS 7.4EG 7.42016-12-15
An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The "defer" servlet offers to redirect a client to a specified URL. Since some checks were missing, arbitrary URLs could be provided as redirection target. Users can b…
- CVE-2016-4075MEDIUMCVSS 6.1EG 6.12017-04-21
Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.
- CVE-2016-4334MEDIUMCVSS 6.1EG 6.12017-04-10
Jive before 2016.3.1 has an open redirect from the external-link.jspa page.
- CVE-2016-4604MEDIUMCVSS 5.4EG 5.42016-07-22
Safari in Apple iOS before 9.3.3 allows remote attackers to spoof the displayed URL via an HTTP response specifying redirection to an invalid TCP port number.
- CVE-2016-4857MEDIUMCVSS 6.1EG 6.12017-05-12
Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.2, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.11 and Splunk Light prior to 6.4.2 allows to redirect users to arbitrary web sites and cond…
- CVE-2016-4859MEDIUMCVSS 6.1EG 6.12017-05-12
Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.3, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.10, Splunk Enterprise 6.1.x prior to 6.1.11, Splunk Enterprise 6.0.x prior to 6.0.12, Splun…
- CVE-2016-5385HIGHCVSS 8.1EG 8.42016-07-19
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remo…
- CVE-2016-5715MEDIUMCVSS 6.1EG 6.12017-01-12
Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in …
- CVE-2016-5878MEDIUMCVSS 6.8EG 6.82016-08-08
Open redirect vulnerability in IBM FileNet Workplace 4.0.2 before 4.0.2.14 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2016-5977MEDIUMCVSS 6.8EG 6.82016-09-26
Open redirect vulnerability in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, an…
- CVE-2016-6020MEDIUMCVSS 6.1EG 6.12017-02-01
IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulne…
- CVE-2016-6154MEDIUMCVSS 6.1EG 6.12019-08-23
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
- CVE-2016-6636MEDIUMCVSS 5.3EG 5.32016-09-30
The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.…
- CVE-2016-6657HIGHCVSS 7.4EG 7.42016-12-16
An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components. Users of affected versions should apply the following mitigation: Upgrade PCF Elastic Runtime 1.8.x versions to 1.8.12 or later. U…
- CVE-2016-6908MEDIUMCVSS 6.1EG 6.12017-01-26
Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to mishandling of several unicode characters such as U+FE70, U+0622, U+0623 etc and how they are r…
- CVE-2016-7137MEDIUMCVSS 6.1EG 6.12017-03-07
Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parame…
- CVE-2016-7831MEDIUMCVSS 6.1EG 6.12017-06-09
Sleipnir 4 Black Edition for Mac 4.5.3 and earlier and Sleipnir 4 for Mac 4.5.3 and earlier (Mac App Store) may allow a remote attacker to spoof the URL display via a specially crafted webpage.
- CVE-2016-8376MEDIUMCVSS 6.1EG 6.12017-02-13
An issue was discovered in Kabona AB WebDatorCentral (WDC) application prior to Version 3.4.0. This non-validated redirect/non-validated forward (OPEN REDIRECT) allows chaining with authenticated vulnerabilities.
- CVE-2016-8947MEDIUMCVSS 6.1EG 6.12017-07-12
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnera…
- CVE-2016-8949MEDIUMCVSS 5.4EG 5.42017-08-09
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could ex…
- CVE-2016-8953MEDIUMCVSS 5.4EG 5.42017-07-12
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnera…
- CVE-2016-8961MEDIUMCVSS 6.1EG 6.12017-02-01
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the…
- CVE-2016-9078HIGHCVSS 8.8EG 8.82018-06-11
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross…
- CVE-2016-9099MEDIUMCVSS 6.1EG 6.12017-05-11
Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 prior to 6.7.2.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6, and ProxySG 6.7 prior to 6.7.2.1 are susceptible to an open redirection vulnerability. A remote attacker can use a crafted ma…
- CVE-2016-9451MEDIUMCVSS 6.8EG 6.82016-11-25
Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.
- CVE-2017-0363MEDIUMCVSS 6.1EG 6.12018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
- CVE-2017-0364MEDIUMCVSS 6.1EG 6.12018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.
- CVE-2017-1000013MEDIUMCVSS 6.1EG 6.12017-07-17
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness
- CVE-2017-1000027MEDIUMCVSS 6.1EG 6.12017-07-17
Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function resulting in unauthorized account access.
- CVE-2017-1000070MEDIUMCVSS 6.1EG 6.12017-07-17
The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819
- CVE-2017-1000117CRITICALCVSS 8.8EG 9.02017-10-05
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodul…
- CVE-2017-1000163MEDIUMCVSS 6.1EG 6.12017-11-17
The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.
- CVE-2017-1000434MEDIUMCVSS 6.1EG 6.12018-01-02
Wordpress plugin Furikake version 0.1.0 is vulnerable to an Open Redirect The furikake-redirect parameter on a page allows for a redirect to an attacker controlled page classes/Furigana.php: header('location:'.urldecode($_GET['furikake-red…
- CVE-2017-1000481MEDIUMCVSS 6.1EG 6.12018-01-03
When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might t…
- CVE-2017-1000484MEDIUMCVSS 6.1EG 6.12018-01-03
By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its own this is not so bad: the attacker could more easily link directly to his own website instead. But in combination wi…
- CVE-2017-1002150MEDIUMCVSS 6.1EG 6.12017-09-14
python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection
- CVE-2017-11482MEDIUMCVSS 6.1EG 6.12017-12-08
The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects t…
- CVE-2017-1156HIGHCVSS 8.8EG 8.82017-05-05
IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to …
- CVE-2017-11586MEDIUMCVSS 6.1EG 6.12017-07-24
dayrui FineCms 5.0.9 has URL Redirector Abuse via the url parameter in a sync action, related to controllers/Weixin.php.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →