Forescout CounterACT - 'a' Open Redirection
Author: Joseph Sheridan type: webapps platform: multiple port: date_added: 2012-11-26 date_updated: 2015-09-02 verified: 1 codes: CVE-2012-4982;OSVDB-87893 tags: aliases: screenshot_url: application_url: raw file: 38062.txt
source: https://www.securityfocus.com/bid/56687/info Forescout CounterACT is prone to an open-redirection vulnerability because the application fails to properly sanitize user-supplied input. A successful exploit may aid in phishing attacks; other attacks are possible. Forescout CounterACT 6.3.4.1 is vulnerable; other versions may also be affected. http://www.example.com/assets/login?a=http://www.evil.com