Nokia Electronic Documentation 5.0 - Connection redirection

Author: @stake
type: remote
platform: windows
port: 
date_added: 2003-09-15  
date_updated: 2012-12-04  
verified: 1  
codes: CVE-2003-0803;OSVDB-3485  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 23148.txt  
source: https://www.securityfocus.com/bid/8625/info

A vulnerability has been discovered in Nokia Electronic Documentation (NED) that may allow an attacker to redirect connections to a third party system. The problem likely occurs due to the NED server failing to sufficiently verify hosts provided within specific HTTP requests. As a result, an attacker may be capable of making a request that would cause data to be redirected to a third party system.

This may allow an attacker to interact with an otherwise inaccessible system, or potentially hide the origin of attacks launched against other targets.

http://www.example.org/docs/NED?action=retrieve&location=http://www.target.com/