.. / CVE-2019-1010290

Exploit for Babel - Open Redirect (CVE-2019-1010290)

Description:

Babel contains an open redirect vulnerability via redirect.php in the newurl parameter. An attacker can use any legitimate site using Babel to redirect user to a malicious site, thus possibly obtaining sensitive information, modifying data, and/or executing unauthorized operations.

Nuclei Template

View the template here CVE-2019-1010290.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-1010290.yaml
Copy

References:

https://untrustednetwork.net/en/2019/02/20/open-redirection-vulnerability-in-babel/
https://github.com/ARPSyndicate/kenzer-templates
http://dev.cmsmadesimple.org/project/files/729
https://nvd.nist.gov/vuln/detail/CVE-2019-1010290