5
CVSSv2

CVE-2005-3634

Published: 16/11/2005 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 up to and including 7.00 allows remote malicious users to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sap sap web application server 6.40

sap sap web application server 7.0

sap sap web application server 6.10

sap sap web application server 6.20

Exploits

source: wwwsecurityfocuscom/bid/15362/info SAP Web Application Server is reported prone to a remote URI redirection vulnerability It is reported that an attacker can exploit this issue by supplying the URI of a malicious site through the 'sap-exiturl' parameter A successful attack may result in various attacks including theft of cooki ...