HIO-2009-0408 Interspire Website Publisher CSRF PDF Print E-mail

Interspire Website Publisher 5.0.5 exhibits a vulnerability which can be exploited by malicious people to conduct cross-site request forgery attacks.

The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited to e.g. perform administrative actions by enticing a logged-in administrator to visit a malicious site.

The vulnerability is reported in version 5.0.5. Other versions may also be affected.

 

References:

CVE-2009-pending

BID:

FrSIRT: N/A

Nessus:N/A

OSVDB: 

SA: 35529

XF: 51285

Related: 

Vendor Solution:


 
< Prev   Next >