"What gets us into trouble is not what we don't know. It's what we know for sure that just ain't so. - Mark Twain"

RSS

HIO-2010-0705 InterPhoto Gallery CSRF Vulnerability PDF Print E-mail

InterPhoto Gallery 2.4.0 interface exhibits vulnerabillities which can be exploited by malicious people to conduct cross-site request forgery attacks.

The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to e.g. create an arbitrary user if a logged-in administrative user visits a malicious web site.

The vulnerability is confirmed in version 2.4.0 Other versions may also be affected.

 

References:

CVE-2010-pending

BID:

OSVDB:

SA: 40537

XF:

Related: 

Vendor Solution:


 
< Prev   Next >