5.8
CVSSv2

CVE-2012-4032

Published: 17/07/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Open redirect vulnerability in the login page in WebsitePanel prior to 1.2.2.1 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in ReturnUrl to Default.aspx.

Vulnerable Product Search on Vulmon Subscribe to Product

websitepanel websitepanel 1.1.0

websitepanel websitepanel 1.0.2

websitepanel websitepanel 1.2.0

websitepanel websitepanel 1.1.2

websitepanel websitepanel 1.0.1

websitepanel websitepanel 1.0.0

websitepanel websitepanel

Exploits

source: wwwsecurityfocuscom/bid/54346/info WebsitePanel is prone to a URI-redirection vulnerability because the application fails to properly sanitize user-supplied input A successful exploit may aid in phishing attacks; other attacks are possible WebsitePanel versions prior to 1221 are vulnerable wwwexamplecom/hosting ...