Werk #1052: index start URL can not be used to redirect to absolute URLs anymore
Component | User interface | ||||||||||||||||||
Title | index start URL can not be used to redirect to absolute URLs anymore | ||||||||||||||||||
Date | Jul 4, 2014 | ||||||||||||||||||
Level | Trivial Change | ||||||||||||||||||
Class | Security Fix | ||||||||||||||||||
Compatibility | Compatible - no manual interaction needed | ||||||||||||||||||
Checkmk versions & editions |
|
An attacker could make a user open up an URL to a compromised website which the does not want to open index.py?start_url=http://(url to compromised URL).