CVE-2009-0347
medium · 5.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.
5.8
CVSS
10.9%
EPSS (exploit prob.)
96th
EPSS percentile
2009-01-29
Published
AV:N/AC:M/Au:N/C:N/I:P/A:P
Weaknesses
CWE-59
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| autonomy | ultraseek | _nil_ |
Check a specific version with /api/v1/cve/match.
References
- http://sunbeltblog.blogspot.com/2009/01/constant-stream-of-ultraseek-redirects.html
- http://www.kb.cert.org/vuls/id/202753
- http://www.securityfocus.com/bid/33500
- http://www.ultraseek.com/forums/thread.jspa?messageID=9818
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48336
- http://sunbeltblog.blogspot.com/2009/01/constant-stream-of-ultraseek-redirects.html
- http://www.kb.cert.org/vuls/id/202753
- http://www.securityfocus.com/bid/33500
- http://www.ultraseek.com/forums/thread.jspa?messageID=9818
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48336
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-0347