Kloxo-MR Cross Site Request Forgery Vulnerability
BID:66818
Info
Kloxo-MR Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 66818 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 12 2014 12:00AM |
| Updated: | Apr 12 2014 12:00AM |
| Credit: | Necmettin Coskun |
| Vulnerable: |
MRatWork Kloxo-MR 6.5.1.b-2014041203 MRatWork Kloxo-MR 6.5.0.f-2014020301 |
| Not Vulnerable: |
MRatWork Kloxo-MR 6.5.1.b-2014041204 |
Exploit / POC
Kloxo-MR Cross Site Request Forgery Vulnerability
To exploit this issue the attacker needs to entice a user into following a malicious URI.
The following exploit is available:
To exploit this issue the attacker needs to entice a user into following a malicious URI.
The following exploit is available:
Solution / Fix
Kloxo-MR Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Kloxo-MR Cross Site Request Forgery Vulnerability
References:
References:
- add isTokenMatch() for 'csrf token'; change protect from 'remote post�?� (Mustafa Ramadhan)
- Kloxo-MR 6.5.0 Final Release! (MRatWork)
- Kloxo-MR Homepage (Mustafa Ramadhan)