CVE-2003-1311

siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder does not ensure that the TARGET parameter names a valid redirection resource, which allows remote attackers to construct a URL that might trick users into visiting an arbitrary web site referenced by this parameter.

Scoring

CVSS base score
0.05
EPSS probability
1.15%
Published
2006-12-15
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs