Vulnerability CVE-2012-6433


Published: 2013-01-03

Description:
Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of administrators for requests that conduct XSS attacks via the news_title parameter in a create action.

See advisories in our WLB2 database:
Topic
Author
Date
Low
e107 v1.0.1 Administrator CSRF Resulting in Arbitrary Javascript Execution
Joshua Reynolds
02.01.2013

Type:

CWE-352

(Cross-Site Request Forgery (CSRF))

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
E107 -> E107 

 References:
http://e107.svn.sourceforge.net/viewvc/e107/trunk/e107_0.7/e107_admin/newspost.php?sortdir=down&r1=12622&r2=12992&sortby=rev
http://www.exploit-db.com/exploits/23828/
http://e107.org/changelog

Copyright 2024, cxsecurity.com

 

Back to Top