Zenoss CVE-2014-9246 Cross Site Request Forgery and Security Bypass Vulnerabilities
BID:71530
Info
Zenoss CVE-2014-9246 Cross Site Request Forgery and Security Bypass Vulnerabilities
| Bugtraq ID: | 71530 |
| Class: | Design Error |
| CVE: |
CVE-2014-9246 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 05 2014 12:00AM |
| Updated: | Dec 05 2014 12:00AM |
| Credit: | Ryan Koppenhaver and Andy Schmitz of Matasano Security. |
| Vulnerable: |
Zenoss Zenoss Core 4.2.4 |
| Not Vulnerable: |
Zenoss Zenoss Core 4.2.5 SP |
Exploit / POC
Zenoss CVE-2014-9246 Cross Site Request Forgery and Security Bypass Vulnerabilities
An attacker can exploit these issues through a browser. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into following a malicious URI.
An attacker can exploit these issues through a browser. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into following a malicious URI.