CGISecurity Logo

Be careful of “scheme relative urls” when performing 3xx redirects

Former coworker Sacha Faust has published an entry on how the lack of handling relative urls when implementing URL redirection can lead to open redirector's.

Article: http://blogs.msdn.com/sfaust/archive/2010/03/30/saferedirect.aspx