CWE-601— URL Redirection to Untrusted Site (Open Redirect)
1,355 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 1 of 28
- CVE-2004-2260NONECVSS 0.0EG 0.02004-12-31
Opera Browser 7.23, and other versions before 7.50, updates the address bar as soon as the user clicks a link, which allows remote attackers to redirect to other sites via the onUnload attribute.
- CVE-2005-0420NONECVSS 0.0EG 0.02005-04-27
Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.
- CVE-2005-10001MEDIUMCVSS 5.4EG 6.12022-03-28
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads t…
- CVE-2005-1475NONECVSS 0.0EG 0.02005-06-16
The XMLHttpRequest object in Opera 8.0 Final Build 1095 allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains via a redirect.
- CVE-2005-4206MEDIUMCVSS 6.1EG 6.12005-12-13
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to framese…
- CVE-2008-1547NONECVSS 0.0EG 0.02008-10-21
Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via …
- CVE-2008-2052MEDIUMCVSS 6.1EG 6.12008-05-02
Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the goto parameter.
- CVE-2009-3832NONECVSS 0.0EG 0.02009-10-30
Opera before 10.01 on Windows does not prevent use of Web fonts in rendering the product's own user interface, which allows remote attackers to spoof the address field via a crafted web site.
- CVE-2010-2471MEDIUMCVSS 6.1EG 6.12019-11-06
Drupal versions 5.x and 6.x has open redirection
- CVE-2010-3661MEDIUMCVSS 6.1EG 6.12019-11-01
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.
- CVE-2010-3669MEDIUMCVSS 5.4EG 5.42019-11-04
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.
- CVE-2010-4266MEDIUMCVSS 6.1EG 6.12021-06-22
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
- CVE-2011-1594MEDIUMCVSS 6.5EG 6.52014-02-05
A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attac…
- CVE-2012-0518MEDIUMCVSS 4.7EG 9.0⚠ KEV2012-10-16
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than…
- CVE-2013-0594MEDIUMCVSS 6.1EG 6.12018-07-11
Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 83383.
- CVE-2013-2621MEDIUMCVSS 6.1EG 6.12020-02-03
Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.
- CVE-2013-2764MEDIUMCVSS 6.1EG 6.12020-01-28
Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default.
- CVE-2014-2213MEDIUMCVSS 6.1EG 6.12019-11-22
Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to portal/scr_sendm…
- CVE-2014-3652MEDIUMCVSS 6.1EG 6.12019-12-15
JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.
- CVE-2014-9617MEDIUMCVSS 6.1EG 6.12020-02-19
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
- CVE-2015-10052MEDIUMCVSS 4.6EG 6.12023-01-15
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, was found in calesanz gibb-modul-151. This affects the function bearbeiten/login. The manipulation leads to open redirect. It is possible to initiate the…
- CVE-2015-10102MEDIUMCVSS 6.3EG 6.32023-04-17
A vulnerability, which was classified as critical, has been found in Freshdesk Plugin 1.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to open redirect. The attack may be launched remotely. Upg…
- CVE-2015-10104LOWCVSS 3.5EG 3.52023-04-30
A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some unknown functionality of the file classes/class-icons-for-features-admin.php. The manipula…
- CVE-2015-10112MEDIUMCVSS 4.3EG 4.32023-06-05
A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_screen_logic of the file wooframework-branding.php. The manipulation of the argument url lead…
- CVE-2015-10113LOWCVSS 3.5EG 3.52023-06-05
A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress. Affected by this vulnerability is the function admin_screen_logic of the file wooframework-tweaks.php. The manipulation of the argu…
- CVE-2015-10114MEDIUMCVSS 4.3EG 4.32023-06-05
A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress. Affected by this issue is the function enable_custom_post_sidebars of the file classes/class-woo-sidebars.php. The manipul…
- CVE-2015-10115MEDIUMCVSS 4.3EG 4.32023-06-05
A vulnerability, which was classified as problematic, was found in WooSidebars Sidebar Manager Converter Plugin up to 1.1.1 on WordPress. This affects the function process_request of the file classes/class-woosidebars-sbm-converter.php. Th…
- CVE-2015-3898MEDIUMCVSS 6.1EG 6.12018-02-28
Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the redirectUrl parameter to (1) bonita/login.jsp o…
- CVE-2015-8094MEDIUMCVSS 6.1EG 6.12018-05-22
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.
- CVE-2015-9540MEDIUMCVSS 6.1EG 6.12020-01-04
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
- CVE-2016-0329MEDIUMCVSS 5.4EG 5.42018-02-02
Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, 10.0.4.0 before 10.0.4.0_iFix8, and 10.1.0.0 before 10.1.0.0_iFix3 allows remote attackers…
- CVE-2016-1000107MEDIUMCVSS 6.1EG 6.12019-12-10
inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to …
- CVE-2016-1000108MEDIUMCVSS 6.1EG 6.12019-12-10
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow …
- CVE-2016-1000110MEDIUMCVSS 6.1EG 6.12019-11-27
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
- CVE-2016-10742MEDIUMCVSS 6.1EG 6.12019-02-17
Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.
- CVE-2016-10769MEDIUMCVSS 6.1EG 6.12019-08-05
cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).
- CVE-2016-15030LOWCVSS 3.5EG 6.12023-03-25
A vulnerability classified as problematic has been found in Arno0x TwoFactorAuth. This affects an unknown part of the file login/login.php. The manipulation of the argument from leads to open redirect. It is possible to initiate the attack…
- CVE-2016-6154MEDIUMCVSS 6.1EG 6.12019-08-23
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
- CVE-2016-9078HIGHCVSS 8.8EG 8.82018-06-11
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross…
- CVE-2017-0363MEDIUMCVSS 6.1EG 6.12018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
- CVE-2017-0364MEDIUMCVSS 6.1EG 6.12018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.
- CVE-2017-1000434MEDIUMCVSS 6.1EG 6.12018-01-02
Wordpress plugin Furikake version 0.1.0 is vulnerable to an Open Redirect The furikake-redirect parameter on a page allows for a redirect to an attacker controlled page classes/Furigana.php: header('location:'.urldecode($_GET['furikake-red…
- CVE-2017-1000481MEDIUMCVSS 6.1EG 6.12018-01-03
When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might t…
- CVE-2017-1000484MEDIUMCVSS 6.1EG 6.12018-01-03
By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its own this is not so bad: the attacker could more easily link directly to his own website instead. But in combination wi…
- CVE-2017-14394MEDIUMCVSS 6.1EG 6.12019-06-19
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via …
- CVE-2017-14802MEDIUMCVSS 5.4EG 6.12018-03-02
Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.
- CVE-2017-1534MEDIUMCVSS 6.1EG 6.12018-01-10
IBM Security Access Manager Appliance 8.0.0 and 9.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit t…
- CVE-2017-15419MEDIUMCVSS 6.5EG 6.52018-08-28
Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.
- CVE-2017-16224MEDIUMCVSS 6.1EG 6.12018-06-07
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to…
- CVE-2017-16652MEDIUMCVSS 6.1EG 6.12018-06-13
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path par…
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →