Open redirect vulnerability in Blue Coat ProxySG 6.5 before 6.5.8.8 and 6.6 and Advanced Secure Gateway (ASG) 6.6 might allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a base64-encoded URL in conjunction with a "clear text" one in a coaching page, as demonstrated by "http://www.%humbug-URL%.local/bluecoat-splash-API?%BASE64-URL%."
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2016-01-08T19:00:00

Updated: 2016-01-08T18:57:01

Reserved: 2015-12-17T00:00:00


Link: CVE-2015-8597

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2016-01-08T19:59:15.100

Modified: 2016-01-13T19:17:37.483


Link: CVE-2015-8597

JSON object: View

cve-icon Redhat Information

No data.