Cisco Identity Services Engine CVE-2012-3908 Multiple Cross Site Request Forgery Vulnerabilities
BID:55602
Info
Cisco Identity Services Engine CVE-2012-3908 Multiple Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 55602 |
| Class: | Design Error |
| CVE: |
CVE-2012-3908 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2012 12:00AM |
| Updated: | Sep 19 2012 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Identity Services Engine CVE-2012-3908 Multiple Cross Site Request Forgery Vulnerabilities
Cisco Identity Services Engine is prone to multiple cross-site request-forgery vulnerabilities.
Exploiting these issues may allow a remote attacker to perform certain actions in the context of an authorized user's session and gain unauthorized access to the affected application; other attacks are also possible.
This issue is being tracked by Cisco Bug ID CSCty46684.
Cisco Identity Services Engine is prone to multiple cross-site request-forgery vulnerabilities.
Exploiting these issues may allow a remote attacker to perform certain actions in the context of an authorized user's session and gain unauthorized access to the affected application; other attacks are also possible.
This issue is being tracked by Cisco Bug ID CSCty46684.
References
Cisco Identity Services Engine CVE-2012-3908 Multiple Cross Site Request Forgery Vulnerabilities
References:
References: