Open forward

From OWASP
Revision as of 07:54, 5 July 2006 by OWASP (Talk | contribs)

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search

Overview

An open forward is an application that takes a parameter and forwards a user to another part of the application without any validation or access control checks. This may allow an attacker to bypass access control checks, especially those enforced externally, such as by a web server.

This article is a stub. You can help OWASP by expanding it or discussing it on its Talk page.


Consequences

Phishing

Exposure period

Platform

Required resources

Severity

Likelihood of exploit

Avoidance and mitigation

Discussion

Examples

http://www.vulnerable.com?forward=/accounts?id=1010

Related problems