Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability."
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15476 | vdb entry signature |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74367 | vdb entry |
http://www.securitytracker.com/id?1026909 | vdb entry third party advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-026 | vendor advisory |
http://osvdb.org/81131 | vdb entry |
http://secunia.com/advisories/48787 | third party advisory |
http://www.securityfocus.com/bid/52903 | vdb entry third party advisory |