Open redirect vulnerability in spyce/examples/redirect.spy in Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
http://securityreason.com/securityalert/3699 | third party advisory |
http://www.procheckup.com/Vulnerability_PR08-01.php | |
http://www.securityfocus.com/archive/1/488336/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/27898 | vdb entry |