gnuboard5
cpe:2.3:a:gnuboard:gnuboard5:*:*:*:*:*:*:*
- 5.5.16
An open redirect vulnerability exists in Gnuboard5 version 5.5.16, allowing remote attackers to obtain sensitive information through the login.php component. The vulnerability arises because the 'url' parameter is not properly sanitized, enabling redirection to arbitrary domains.
Exploitation of this vulnerability could lead to phishing attacks by redirecting users to malicious sites.
The vulnerability can be reproduced by sending a request to 'login.php' with a 'url' parameter that includes a backslash followed by a desired domain, such as 'google.com' or 'github.com'.
Users are advised to update to Gnuboard5 version 5.5.17, which addresses this open redirect vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.