CVE-2005-3634
published 2005-11-16CVE-2005-3634: frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary…
PriorityP430medium5CVSS 2.0
AVNACLAuNCNIPAN
EXPLOIT
EPSS
19.38%
97.0th percentile
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | sap_web_application_server | — | — |
| sap | sap_web_application_server | — | — |
| sap | sap_web_application_server | — | — |
| sap | sap_web_application_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8648-qmcx-pvc2: frameset
ghsa_unreviewed·2022-05-01
CVE-2005-3634 [MEDIUM] GHSA-8648-qmcx-pvc2: frameset
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.
Red Hat
CVE-2007-3635: Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin before 2
vendor_redhat·CVSS 9.3
CVE-2007-3635 [CRITICAL] CVE-2007-3635: Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin before 2
Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin before 2.1 for Squirrelmail might allow "local authenticated users" to inject certain commands via unspecified vectors. NOTE: this might overlap CVE-2005-1924, CVE-2006-4169, or CVE-2007-3634.
Statement: Not vulnerable. This plugin is not shipped with Squirrelmail in Red Hat Enterprise Linux.
No detection rules found.
Exploit-DB
SAP Web Application Server 6.x/7.0 - Open Redirection
exploitdb·2005-11-09
CVE-2005-3634 SAP Web Application Server 6.x/7.0 - Open Redirection
SAP Web Application Server 6.x/7.0 - Open Redirection
---
source: https://www.securityfocus.com/bid/15362/info
SAP Web Application Server is reported prone to a remote URI redirection vulnerability.
It is reported that an attacker can exploit this issue by supplying the URI of a malicious site through the 'sap-exiturl' parameter.
A successful attack may result in various attacks including theft of cookie-based authentication credentials. An attacker may also be able to exploit this vulnerability to enhance phishing style attacks.
This issue only affects the BSP runtime of SAP WAS.
http://www.example.com/sap/bc/BSp/sap/menu/fameset.htm?sap--essioncmd=close&sapexiturl=http%3a%2f%2fwww.example.com
Nuclei
SAP Web Application Server 6.x/7.0 - Open Redirect
nuclei·CVSS 5.0
CVE-2005-3634 [MEDIUM] SAP Web Application Server 6.x/7.0 - Open Redirect
SAP Web Application Server 6.x/7.0 - Open Redirect
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.
Template:
id: CVE-2005-3634
info:
name: SAP Web Application Server 6.x/7.0 - Open Redirect
author: ctflearner
severity: medium
description: |
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.
impact: |
An attacker can exploit this vulnerability to redirect users to malicious
http://marc.info/?l=bugtraq&m=113156525006667&w=2http://secunia.com/advisories/17515/http://securityreason.com/securityalert/163http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Multiple_XSS_in_SAP_WAS.pdfhttp://www.securityfocus.com/bid/15362http://www.securitytracker.com/alerts/2005/Nov/1015174.htmlhttp://www.vupen.com/english/advisories/2005/2361https://exchange.xforce.ibmcloud.com/vulnerabilities/23031http://marc.info/?l=bugtraq&m=113156525006667&w=2http://secunia.com/advisories/17515/http://securityreason.com/securityalert/163http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_Multiple_XSS_in_SAP_WAS.pdfhttp://www.securityfocus.com/bid/15362http://www.securitytracker.com/alerts/2005/Nov/1015174.htmlhttp://www.vupen.com/english/advisories/2005/2361https://exchange.xforce.ibmcloud.com/vulnerabilities/23031
2005-11-16
Published