Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-0711

Опубликовано: 25 фев. 2010
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to hijack the authentication of an administrator for requests that (1) delete users via the delete action in the ma2 parameter or (2) create administrators via the update action in the ma2 parameter.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:aspcodecms:aspcode_cms:1.5.8:*:*:*:*:*:*:*
cpe:2.3:a:aspcodecms:aspcode_cms:2.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 51%
0.00282
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

github
почти 4 года назад

Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to hijack the authentication of an administrator for requests that (1) delete users via the delete action in the ma2 parameter or (2) create administrators via the update action in the ma2 parameter.

EPSS

Процентиль: 51%
0.00282
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-352