PT-2007-6740 · Flatnuke · Flatnuke
Kingoftheworld
·
Publicado
2007-11-01
·
Atualizado
2017-09-29
·
CVE-2007-5773
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Flatnuke version 3
Description
A cross-site request forgery (CSRF) issue exists, allowing remote attackers to perform actions as administrators. This is achieved through requests that contain the pathname in the
dir parameter and the filename in the ffile parameter.Recommendations
For Flatnuke version 3, consider restricting access to the File Manager module until a fix is available. As a temporary workaround, avoid using the
dir and ffile parameters in requests to the index.php file.Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Flatnuke