Vulnerability Note VU#202753
Autonomy Ultraseek URL redirection vulnerability
Overview
The Autonomy Ultraseek search engine contains a URL redirection vulnerability that may allow an attacker to redirect website users to other sites.
Description
The Autonomy Ultraseek search engine contains a URL redirection vulnerability in the /cs.html?url= paramater. The destination URL can be obsfucated in the redirect by using URL encoding techniques. To exploit this issue, an attacker would need to get a user to click on a link or browse to a website. |
Impact
An attacker may be able to redirect a user to any website. |
Solution
Ultraseek administrators should contact Ultraseek support for information on how to obtain updated software that addresses this issue. |
Workarounds |
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Ultraseek | Vulnerable | 08 Jan 2009 | 28 Jan 2009 |
| Verity, Inc. | Vulnerable | 08 Jan 2009 | 28 Jan 2009 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.ultraseek.com/forums/thread.jspa?messageID=9818
- http://www.ultraseek.com/articles/archives/2006/01/quick_links_in.html
- http://www.owasp.org/index.php/Open_redirect
- http://sunbeltblog.blogspot.com/2009/01/constant-stream-of-ultraseek-redirects.html
Credit
This document was written by Ryan Giobbi.
Other Information
- CVE IDs: Unknown
- Date Public: 11 Jan 2009
- Date First Published: 28 Jan 2009
- Date Last Updated: 28 Jan 2009
- Severity Metric: 1.30
- Document Revision: 14
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.
This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify