Rapid7 Nexpose CVE-2017-5264 Cross Site Request Forgery Vulnerability
BID:102208
CVE-2017-5264 |Info
Rapid7 Nexpose CVE-2017-5264 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 102208 |
| Class: | Unknown |
| CVE: |
CVE-2017-5264 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2017 12:00AM |
| Updated: | Dec 19 2017 09:01PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Rapid7 Nexpose 6.4.65 Rapid7 Nexpose 6.4.13 Rapid7 Nexpose 6.4.12 Rapid7 Nexpose 5.8.6 Rapid7 Nexpose 5.8 Rapid7 Nexpose 5.7.5 Rapid7 Nexpose 5.5.4 Rapid7 Nexpose 5.5.3 Rapid7 Nexpose 5.4.8 Rapid7 Nexpose 5.4.7 Rapid7 Nexpose 5.4.6 Rapid7 Nexpose 5.5.8 Rapid7 Nexpose 5.5.7 Rapid7 Nexpose 5.5.6 Rapid7 Nexpose 5.5.5 Rapid7 Nexpose 5.5.1 Rapid7 Nexpose 5.4.9 Rapid7 Nexpose 5.4.5 Rapid7 Nexpose 5.4.4 Rapid7 Nexpose 5.4.3 Rapid7 Nexpose 5.4.2 Rapid7 Nexpose 5.4.12 Rapid7 Nexpose 5.4.11 Rapid7 Nexpose 5.4.10 Rapid7 Nexpose 5.4.1 Rapid7 Nexpose 5.4 |
| Not Vulnerable: |
Rapid7 Nexpose 6.4.66 |
Discussion
Rapid7 Nexpose CVE-2017-5264 Cross Site Request Forgery Vulnerability
Nexpose is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Versions prior to Nexpose 6.4.66 are vulnerable.
Nexpose is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Versions prior to Nexpose 6.4.66 are vulnerable.
Exploit / POC
Rapid7 Nexpose CVE-2017-5264 Cross Site Request Forgery Vulnerability
An attacker can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Rapid7 Nexpose CVE-2017-5264 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.