Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Open redirect vulnerability in zport/acl_users/cookieAuthHelper/login_form in Zenoss 4.2.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the came_from parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zenoss 开放重定向漏洞
Vulnerability Description
Zenoss是美国Zenoss公司的一套开源的企业级IT管理和监控软件。该软件通过单一的Web控制台监控网络架构的状态和健康指数。 Zenoss 4.2.5版本的zport/acl_users/cookieAuthHelper/login_form脚本中存在开放重定向漏洞。远程攻击者可借助‘came_from’参数中的UTL利用该漏洞重定向用户到任意网站,进而实施钓鱼攻击。
CVSS Information
N/A
Vulnerability Type
N/A