mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-11 00:14:52 +02:00
19 lines
833 B
Markdown
19 lines
833 B
Markdown
### [CVE-2014-7294](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7294)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Open redirect vulnerability in the logon page in NYU OpenSSO Integration 2.1 and earlier for Ex Libris Patron Directory Services (PDS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://packetstormsecurity.com/files/129756/Ex-Libris-Patron-Directory-Services-2.1-Open-Redirect.html
|
|
- http://seclists.org/fulldisclosure/2014/Dec/127
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|