Cross-site request forgery (CSRF)... CVE-2011-2191

6.8 AV AC AU C I A
发布: 2011-10-07
修订: 2011-11-24

Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences, as demonstrated by a crafted nickname field to vserver/apply.

0%
暂无可用Exp或PoC
当前有137条受影响产品信息