PT-2007-7324 · Falcon · Falcon Series One Cms

Mhz91

·

Publicado

2007-12-20

·

Atualizado

2017-09-29

·

CVE-2007-6490

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Falcon Series One CMS version 1.4.3
Description A cross-site request forgery (CSRF) issue allows remote attackers to change a password via a certain "changepass" action to "index.php".
Recommendations For Falcon Series One CMS version 1.4.3, update to a version that fixes this issue, as using the "changepass" action in "index.php" can lead to unauthorized password changes.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6490

Produtos afetados

Falcon Series One Cms