5.8
CVSSv2

CVE-2008-7269

Published: 01/12/2010 Updated: 11/10/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the forward parameter in a logout action.

Vulnerable Product Search on Vulmon Subscribe to Product

boka siteengine 5.0

Exploits

source: wwwsecurityfocuscom/bid/31888/info SiteEngine is prone to a remote URI-redirection vulnerability because the application fails to properly sanitize user-supplied input A successful exploit may aid in phishing-style attacks SiteEngine 50 is vulnerable; other versions may also be affected wwwexamplecom/apiphp?action ...