CVE-2015-0706
published 2015-04-23CVE-2015-0706: Open redirect vulnerability in Cisco FireSIGHT System Software 5.3.1.1, 5.3.1.2, and 6.0.0 in FireSIGHT Management Center allows remote attackers to redirect…
PriorityP425medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.10%
62.1th percentile
Open redirect vulnerability in Cisco FireSIGHT System Software 5.3.1.1, 5.3.1.2, and 6.0.0 in FireSIGHT Management Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted HTTP header, aka Bug IDs CSCut06060, CSCut06056, and CSCus98966.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
| cisco | firesight_system_software | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_cisco5.8MEDIUM
vendor_apache4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p9cg-9qh9-4f4v: Open redirect vulnerability in Cisco FireSIGHT System Software 5
ghsa_unreviewed·2022-05-17
CVE-2015-0706 [MEDIUM] GHSA-p9cg-9qh9-4f4v: Open redirect vulnerability in Cisco FireSIGHT System Software 5
Open redirect vulnerability in Cisco FireSIGHT System Software 5.3.1.1, 5.3.1.2, and 6.0.0 in FireSIGHT Management Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted HTTP header, aka Bug IDs CSCut06060, CSCut06056, and CSCus98966.
Cisco
Cisco FireSIGHT Management Center Web Framework HTTP Header Redirection Vulnerability
vendor_cisco·2015-04-22·CVSS 5.8
CVE-2015-0706 [MEDIUM] CWE-20 Cisco FireSIGHT Management Center Web Framework HTTP Header Redirection Vulnerability
Cisco FireSIGHT Management Center Web Framework HTTP Header Redirection Vulnerability
A vulnerability in the web framework of Cisco FireSIGHT Management Center could allow an unauthenticated, remote attacker to inject a crafted HTTP header that causes users to be redirected to a malicious website.
The vulnerability is due to insufficient validation of user input before it is used as an HTTP header value. An attacker could exploit this vulnerability by persuading a user to access a crafted URL. A successful exploit could allow the attacker to conduct a web page redirection attack.
Cisco has confirmed the vulnerability and released software updates.
To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instru
Apache
Apache tomcat: CVE-2016-0706
vendor_apache·CVSS 4.3
CVE-2016-0706 [MEDIUM] Apache tomcat: CVE-2016-0706
Apache tomcat: CVE-2016-0706
This issue only affects users running untrusted web applications under a security manager. The internal StatusManagerServlet could be loaded by a malicious web application when a security manager was configured. This servlet could then provide the malicious web application with a list of all deployed applications and a list of the HTTP request lines for all requests currently being processed. This could have exposed sensitive information from other web applications, such as session IDs, to the web application. This was fixed in revision 1722800 . This issue was identified by the Tomcat security team on 27 December 2015 and made public on 22 February 2016. Affects: 8.0.0.RC1 to 8.0.30 Moderate: Security Manager bypass
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-23
Published