PT-2008-2584 · Python · Spyce

Bruno Kovacs

+2

·

Published

2008-02-25

·

Updated

2018-10-15

·

CVE-2008-0981

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Spyce - Python Server Pages (PSP) version 2.1.3
Description The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter. This can be exploited by providing a malicious URL to the vulnerable application.
Recommendations For Spyce - Python Server Pages (PSP) version 2.1.3, consider validating and sanitizing the url parameter to prevent redirects to arbitrary web sites. As a temporary workaround, restrict access to the redirect functionality to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0981

Affected Products

Spyce