PT-2007-6163 · Xcms · Xcms

X0Kster

·

Published

2007-09-24

·

Updated

2018-10-15

·

CVE-2007-5060

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions XCMS (affected versions not specified)
Description A cross-site request forgery (CSRF) issue exists in the cpass functionality of an admin action in index.php, allowing remote attackers to change arbitrary passwords. This is possibly related to certain password and rpassword parameters, as well as timestamp values.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5060

Affected Products

Xcms