Sun Java Web Console BeginLogin.jsp redirect_url Parameter URI Redirection

This script is Copyright (C) 2011-2014 Tenable Network Security, Inc.

Synopsis :

The remote web server has a URI redirection vulnerability.

Description :

The version of Sun Java Web Console running on the remote host may
have a URI redirection vulnerability. An attacker could exploit this
by tricking a user into requesting a specially crafted URL, which
would redirect the user to an arbitrary website. This could result
in further attacks (e.g. phishing).

See also :

Solution :

Apply the relevant patch referenced in Sun Alert 243786.

Risk factor :

Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.2
Public Exploit Available : false

Family: Web Servers

Nessus Plugin ID: 17725 ()

Bugtraq ID: 32771

CVE ID: CVE-2008-5550

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now