Mongoose Web Server CVE-2017-11567 Cross Site Request Forgery Vulnerability
BID:100830
Info
Mongoose Web Server CVE-2017-11567 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 100830 |
| Class: | Design Error |
| CVE: |
CVE-2017-11567 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2017 12:00AM |
| Updated: | Sep 07 2017 12:00AM |
| Credit: | John Page AKA hyp3rlinx. |
| Vulnerable: |
Cesanta Mongoose Web Server 6.5 |
| Not Vulnerable: |
Cesanta Mongoose Web Server 6.9 |
Discussion
Mongoose Web Server CVE-2017-11567 Cross Site Request Forgery Vulnerability
Mongoose Web Server is prone to an unspecified cross-site request-forgery vulnerability because the application fails to properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Mongoose Web Server prior to 6.9 are vulnerable.
Mongoose Web Server is prone to an unspecified cross-site request-forgery vulnerability because the application fails to properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Mongoose Web Server prior to 6.9 are vulnerable.
Exploit / POC
Mongoose Web Server CVE-2017-11567 Cross Site Request Forgery Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Mongoose Web Server CVE-2017-11567 Cross Site Request Forgery Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Mongoose Web Server CVE-2017-11567 Cross Site Request Forgery Vulnerability
References:
References:
- Cesanta Homepage (Cesanta)
- CVE-2017-11567 Mongoose Web Server v6.5 CSRF Command Execution (Seclists.org)
- CVE-2017-11567 Mongoose Web Server v6.5 CSRF Command Execution (Altervista)