PT-2012-2479 · Symantec · Symantec Message Filter+1
Publicado
2012-07-05
·
Atualizado
2012-07-06
·
CVE-2012-0303
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Symantec Message Filter version 6.3
Description
The issue concerns multiple cross-site request forgery (CSRF) vulnerabilities in the Brightmail Control Center component. These vulnerabilities allow remote attackers to hijack the authentication of arbitrary users, enabling them to execute application commands or create admin accounts.
Recommendations
For Symantec Message Filter version 6.3, consider disabling access to the Brightmail Control Center until a patch is available to prevent potential exploitation of the CSRF vulnerabilities. Restrict access to admin account creation and application command execution to minimize the risk of unauthorized actions.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Brightmail Control Center
Symantec Message Filter