Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Open redirect vulnerability in the login form in Zenoss Core before 4.2.5 SP161 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the came_from parameter, aka ZEN-11998.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zenoss Core 开放重定向漏洞
Vulnerability Description
Zenoss Core是美国Zenoss公司的一套开源的企业级IT管理和监控软件。该软件通过单一的Web控制台监控网络架构的状态和健康指数。 Zenoss Core 4.2.5 SP161之前版本的登录表单中存在开放重定向漏洞。远程攻击者可借助‘came_from’参数利用该漏洞将用户重定向到任意网站,实施钓鱼攻击。
CVSS Information
N/A
Vulnerability Type
N/A