This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Open redirect
From OWASP
[hide]
Overview
An open redirect is an application that takes a parameter and redirects a user to the parameter value without any validation. This vulnerability is used in phishing attacks to get users to visit malicious sites without realizing it.
This article is a stub. You can help OWASP by expanding it or discussing it on its Talk page.
Consequences
Exposure period
Platform
Required resources
Severity
Likelihood of exploit
Avoidance and mitigation
Discussion
Examples
http://www.vulnerable.com?redirect=http://www.attacker.com