PT-2012-4424 · Cerberus · Cerberus Ftp Server

Redro0Cky

·

Published

2012-10-04

·

Updated

2013-02-07

·

CVE-2012-2999

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cerberus FTP Server versions prior to 5.0.5.0
Description The issue affects the web interface of the software, where multiple cross-site request forgery (CSRF) vulnerabilities are present. These vulnerabilities allow remote attackers to hijack the authentication of administrators for specific requests, such as adding a user account or reconfiguring the state of the FTP service. This can be achieved through requests to specific endpoints, for example, "usermanager/users/modify".
Recommendations For versions prior to 5.0.5.0, update to version 5.0.5.0 or later to resolve the issue.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2999

Affected Products

Cerberus Ftp Server