An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://sir.kr/g5_pds/7205 | patch |
https://github.com/gnuboard/gnuboard5/issues/319 | issue tracking exploit vendor advisory |