|
|
|
![]() |
Vulnerability Note VU#202753Autonomy Ultraseek URL redirection vulnerabilityOverviewThe Autonomy Ultraseek search engine contains a URL redirection vulnerability that may allow an attacker to redirect website users to other sites.I. DescriptionThe Autonomy Ultraseek search engine contains a URL redirection vulnerability in the /cs.html?url= paramater. The destination URL can be obsfucated in the redirect by using URL encoding techniques. To exploit this issue, an attacker would need to get a user to click on a link or browse to a website.II. ImpactAn attacker may be able to redirect a user to any website.III. SolutionUltraseek administrators should contact Ultraseek support for information on how to obtain updated software that addresses this issue.Workarounds
References
This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||