e-Pares Unspecified Cross Site Request Forgery Vulnerability
BID:40517
Info
e-Pares Unspecified Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 40517 |
| Class: | Design Error |
| CVE: |
CVE-2010-2151 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Yamaya Akira |
| Vulnerable: |
Fujitsu e-Pares L40 Fujitsu e-Pares L30 Fujitsu e-Pares L20 Fujitsu e-Pares L10 Fujitsu e-Pares L03 Fujitsu e-Pares L01 Fujitsu e-Pares 01 |
| Not Vulnerable: | |
Discussion
e-Pares Unspecified Cross Site Request Forgery Vulnerability
e-Pares is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application. Other attacks are also possible.
e-Pares 01, L01, L03, L10, L20, L30, and L40 are vulnerable; other versions may be affected.
e-Pares is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application. Other attacks are also possible.
e-Pares 01, L01, L03, L10, L20, L30, and L40 are vulnerable; other versions may be affected.
Exploit / POC
e-Pares Unspecified Cross Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
e-Pares Unspecified Cross Site Request Forgery Vulnerability
Solution:
Reports indicate vendor updates are available; this has not been confirmed. Contact the vendor for more information.
Solution:
Reports indicate vendor updates are available; this has not been confirmed. Contact the vendor for more information.
References
e-Pares Unspecified Cross Site Request Forgery Vulnerability
References:
References:
- e-Pares - Homepage (Fujitsu)
- e-Pares cross-site vulnerability (JPCERT)