6.8

CVE-2009-3248

Exploit
Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VtigerVtiger Crm Version5.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.26% 0.657
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

http://secunia.com/advisories/36309
Vendor Advisory
http://www.exploit-db.com/exploits/9450
http://www.securityfocus.com/bid/36062
Exploit
http://www.ush.it/2009/08/18/vtiger-crm-504-multiple-vulnerabilities/
Exploit
http://www.ush.it/team/ush/hack-vtigercrm_504/vtigercrm_504.txt
Exploit
http://www.vupen.com/english/advisories/2009/2319
Vendor Advisory
http://marc.info/?l=bugtraq&m=125060676515670&w=2
Exploit
http://www.osvdb.org/57238
Exploit