CWE Database
/

CWE-698

Back to CWE list

CWE-698

Execution After Redirect (EAR)

Base
Incomplete

Description

The web application sends a redirect to another location, but instead of exiting, it executes additional code.

Common Consequences

Scope

Other
Confidentiality
Integrity
Availability

Impact

Alter Execution Logic, Execute Unauthorized Code or Commands

CVE-2013-1402

Execution-after-redirect allows access to application configuration details.

CVE-2009-1936

chain: library file sends a redirect if it is directly requested but continues to execute, allowing remote file inclusion and path traversal.

CVE-2007-2713

Remote attackers can obtain access to administrator functionality through EAR.

CVE-2007-4932

Remote attackers can obtain access to administrator functionality through EAR.

CVE-2007-5578

Bypass of authentication step through EAR.

CVE-2007-2713

Chain: Execution after redirect triggers eval injection.

CVE-2007-6652

chain: execution after redirect allows non-administrator to perform static code injection.

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now