Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-2522

Опубликовано: 29 июл. 2011
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 6.8

Описание

Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.

РелизСтатусПримечание
devel

not-affected

2:3.5.11~dfsg-1ubuntu1
hardy

released

3.0.28a-1ubuntu4.15
lucid

released

2:3.4.7~dfsg-1ubuntu3.7
maverick

released

2:3.5.4~dfsg-1ubuntu8.5
natty

released

2:3.5.8~dfsg-1ubuntu2.3
upstream

released

3.5.10

Показывать по

EPSS

Процентиль: 96%
0.3021
Средний

6.8 Medium

CVSS2

Связанные уязвимости

redhat
почти 14 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.

nvd
почти 14 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.

debian
почти 14 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Samb ...

github
около 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.

oracle-oval
почти 14 лет назад

ELSA-2011-1220: samba3x security update (MODERATE)

EPSS

Процентиль: 96%
0.3021
Средний

6.8 Medium

CVSS2