HP Systems Insight Manager CVE-2011-1543 Unspecified Cross Site Request Forgery Vulnerability
BID:47513
Info
HP Systems Insight Manager CVE-2011-1543 Unspecified Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 47513 |
| Class: | Design Error |
| CVE: |
CVE-2011-1543 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 20 2011 12:00AM |
| Updated: | Apr 20 2011 12:00AM |
| Credit: | HP |
| Vulnerable: |
HP Systems Insight Manager 6.2 HP Systems Insight Manager 6.1 HP Systems Insight Manager 6.0.0.96 HP Systems Insight Manager 6.0 HP Systems Insight Manager 5.3 Update 1 HP Systems Insight Manager 5.3 HP Systems Insight Manager 5.2 SP2 HP Systems Insight Manager 5.1 SP1 HP Systems Insight Manager 5.0 SP6 HP Systems Insight Manager 5.0 SP5 HP Systems Insight Manager 5.0 SP3 HP Systems Insight Manager 5.0 SP2 HP Systems Insight Manager 5.0 SP1 HP Systems Insight Manager 5.0 HP Systems Insight Manager 4.2 SP2 HP Systems Insight Manager 4.2 SP1 HP Systems Insight Manager 4.2 |
| Not Vulnerable: |
HP Systems Insight Manager 6.3 |
Discussion
HP Systems Insight Manager CVE-2011-1543 Unspecified Cross Site Request Forgery Vulnerability
HP Systems Insight Manager is prone to a cross-site request-forgery vulnerability.
An attacker can exploit this issue to perform unauthorized actions by enticing a logged-in user to visit a malicious site.
Versions prior to Systems Insight Manager 6.3 are vulnerable.
HP Systems Insight Manager is prone to a cross-site request-forgery vulnerability.
An attacker can exploit this issue to perform unauthorized actions by enticing a logged-in user to visit a malicious site.
Versions prior to Systems Insight Manager 6.3 are vulnerable.
Exploit / POC
HP Systems Insight Manager CVE-2011-1543 Unspecified Cross Site Request Forgery Vulnerability
To exploit the issue, an attacker must entice a user into visiting a malicious site.
To exploit the issue, an attacker must entice a user into visiting a malicious site.
Solution / Fix
HP Systems Insight Manager CVE-2011-1543 Unspecified Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
HP Systems Insight Manager CVE-2011-1543 Unspecified Cross Site Request Forgery Vulnerability
References:
References: