Sign in
CVE-2009-4907
CVE-2009-4907
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in oBlog allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) force an admin logout, (3) change the visibility of posts, (4) remove links, and (5) change the name fields of a blog.
Impact
CVSS v2 : 6.8 MEDIUM
Type
CWE-352
Attack Vector
CVSSv2 Vector : AV:N/AC:M/Au:N/C:P/I:P/A:P
Quick links
CVE
,
NVD
,
CERT
,
Metasploit
,
Exploit-db
,
Fulldisc
,
Bugtraq
,
Microsoft
,
Red Hat
,
Debian
, GitHub
code
/
issues
,
Google
References
http://osvdb.org/60907
http://packetstormsecurity.org/0912-exploits/oblog-xssxsrf.txt
http://secunia.com/advisories/37661
https://exchange.xforce.ibmcloud.com/vulnerabilities/54714
FAQ
Terms of service
Privacy policy