VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-2289
secure_access: Open redirect vulnerability in dana/home/homepage.c...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2289

Original

Open redirect vulnerability in dana/home/homepage.cgi in Juniper Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Location parameter.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-06-15
Source Information Category:
Advisory, Alert
Last Updated:
2010-06-15




Affected Product Tags
cpe:/a:juniper:secure_access:6.5:r1.0
cpe:/a:juniper:secure_access:6.5:r2.0
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

Alternatives




References
BID 40729




BUGTRAQ 20100610 PR09-17: Juniper Secure Access seriers (Juniper IVE) authenticated XSS & REDIRECTION




MISC http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr09-17




MISC http://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2010-05-751&viewMode=view




OSVDB 65289




SECUNIA 40117




VUPEN ADV-2010-1420




Vulnerability Type Input Validation (CWE-20)




XF juniper-homepage-spoofing(59284)





Copyright © 2010 JPCERT/CC All Rights Reserved.