Overview
The Autonomy Ultraseek search engine contains a URL redirection vulnerability that may allow an attacker to redirect website users to other sites.
Description
The Autonomy Ultraseek search engine contains a URL redirection vulnerability in the /cs.html?url= paramater. The destination URL can be obsfucated in the redirect by using URL encoding techniques. To exploit this issue, an attacker would need to get a user to click on a link or browse to a website. |
Impact
An attacker may be able to redirect a user to any website. |
Solution
Ultraseek administrators should contact Ultraseek support for information on how to obtain updated software that addresses this issue. |
Workarounds |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- |
Temporal | 0 | E:ND/RL:ND/RC:ND |
Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | None |
Severity Metric: | 1.30 |
Date Public: | 2009-01-11 |
Date First Published: | 2009-01-28 |
Date Last Updated: | 2009-01-28 21:19 UTC |
Document Revision: | 19 |