[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2510-1 extplorer -- Cross-site request forgery

ID: oval:org.secpod.oval:def:600848Date: (C)2012-07-18   (M)2022-10-10
Class: PATCHFamily: unix




John Leitch has discovered a vulnerability in eXtplorer, a very feature rich web server file manager, which can be exploited by malicious people to conduct cross-site request forgery attacks. The vulnerability allows users to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited for example, to create an administrative user account by tricking an logged administrator to visiting an attacker-defined web link.

Platform:
Debian 6.0
Product:
extplorer
Reference:
DSA-2510-1
CVE-2012-3362
CVE    1
CVE-2012-3362
CPE    3
cpe:/a:extplorer:extplorer:2.1.0:rc3
cpe:/a:extplorer:extplorer
cpe:/o:debian:debian_linux:6.0

© SecPod Technologies