HP Insight Software Installer for Windows Unspecified Cross Site Request Forgery Vulnerability
BID:41584
Info
HP Insight Software Installer for Windows Unspecified Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 41584 |
| Class: | Access Validation Error |
| CVE: |
CVE-2010-1968 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2010 12:00AM |
| Updated: | Jul 13 2010 12:00AM |
| Credit: | HP |
| Vulnerable: |
HP Insight Software Installer for Windows 6.0 |
| Not Vulnerable: |
HP Insight Software Installer for Windows 6.1 |
Discussion
HP Insight Software Installer for Windows Unspecified Cross Site Request Forgery Vulnerability
HP Insight Software Installer for Windows is prone to a cross-site request-forgery vulnerability.
Attackers can exploit this issue to perform certain administrative actions and gain unauthorized access to the affected application.
Versions prior to Insight Software Installer for Windows 6.1 are vulnerable.
HP Insight Software Installer for Windows is prone to a cross-site request-forgery vulnerability.
Attackers can exploit this issue to perform certain administrative actions and gain unauthorized access to the affected application.
Versions prior to Insight Software Installer for Windows 6.1 are vulnerable.
Exploit / POC
HP Insight Software Installer for Windows Unspecified Cross Site Request Forgery Vulnerability
To exploit the issue, an attacker must entice an unsuspecting user into visiting a malicious website.
To exploit the issue, an attacker must entice an unsuspecting user into visiting a malicious website.