Overview
The Autonomy Ultraseek search engine contains a URL redirection vulnerability that may allow an attacker to redirect website users to other sites.
Description
The Autonomy Ultraseek search engine contains a URL redirection vulnerability in the /cs.html?url= paramater. The destination URL can be obsfucated in the redirect by using URL encoding techniques. To exploit this issue, an attacker would need to get a user to click on a link or browse to a website.  | 
Impact
An attacker may be able to redirect a user to any website.  | 
Solution
Ultraseek administrators should contact Ultraseek support for information on how to obtain updated software that addresses this issue.  | 
Workarounds   | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- | 
| Temporal | 0 | E:ND/RL:ND/RC:ND | 
| Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND | 
References
Acknowledgements
This document was written by Ryan Giobbi.
Other Information
| CVE IDs: | None | 
| Severity Metric: | 1.30 | 
| Date Public: | 2009-01-11 | 
| Date First Published: | 2009-01-28 | 
| Date Last Updated: | 2009-01-28 21:19 UTC | 
| Document Revision: | 19 |