CVE-2010-2289
Last modified
CVE-2010-2289 is a vulnerability of currently unknown severity. Open redirect vulnerability in dana/home/homepage.cgi in Juniper Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Location parameter.. EPSS estimates a 1.36% chance of exploitation in the next 30 days.
Description
Open redirect vulnerability in dana/home/homepage.cgi in Juniper Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Location parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Juniper | Secure Access | 6.5 | R1.0 |
References
- http://osvdb.org/65289Exploit
- http://secunia.com/advisories/40117Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1420Vendor Advisory
- http://osvdb.org/65289Exploit
- http://secunia.com/advisories/40117Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1420Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-2289?
How severe is CVE-2010-2289?
How do I fix CVE-2010-2289?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-2283The SMB dissector in Wireshark 0.99.6 through 1.0.13, and 1.…
- CVE-2010-2284Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10…
- CVE-2010-2285The SMB PIPE dissector in Wireshark 0.8.20 through 1.0.13 an…
- CVE-2010-2286The SigComp Universal Decompressor Virtual Machine dissector…
- CVE-2010-2287Buffer overflow in the SigComp Universal Decompressor Virtua…
- CVE-2010-2288Cross-site scripting (XSS) vulnerability in dana/nc/ncrun.cg…
- CVE-2010-2290Cross-site scripting (XSS) vulnerability in cgi-bin/cgix/hel…
- CVE-2010-2291Unspecified vulnerability in the web interface in snom VoIP …
- CVE-2010-2292Cross-site scripting (XSS) vulnerability in the Ping tools w…
- CVE-2010-2293The Ping tools web interface in Dlink Di-604 router allows r…
- CVE-2010-2294Cross-site request forgery (CSRF) vulnerability in Plume CMS…
- CVE-2010-2295page/EventHandler.cpp in WebCore in WebKit in Google Chrome …
Are you affected by CVE-2010-2289?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
