PT-2010-1710 · Oblog · Oblog

Published

2010-06-25

·

Updated

2017-08-17

·

CVE-2009-4907

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions oblog (affected versions not specified)
Description The issue allows remote attackers to hijack the authentication of administrators for various requests, including changing the admin password, forcing an admin logout, changing the visibility of posts, removing links, and changing the name fields of a blog.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4907

Affected Products

Oblog