CVE-2012-1058
N/A
N/A
Summary
Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an admin.newuser action to index.php.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.exploit-db.com/exploits/18468
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73051
- http://secunia.com/advisories/47881
- http://osvdb.org/78923
- http://packetstormsecurity.org/files/109507/Flyspray-0.9.9.6-Cross-Site-Request-Forgery.html
References
- http://www.exploit-db.com/exploits/18468
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73051
- http://secunia.com/advisories/47881
- http://osvdb.org/78923
- http://packetstormsecurity.org/files/109507/Flyspray-0.9.9.6-Cross-Site-Request-Forgery.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.