Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/15596 | third party advisory vdb entry |
http://secunia.com/advisories/11195 | third party advisory broken link |
http://marc.info/?l=bugtraq&m=108006309112075&w=2 | mailing list |
http://www.securityfocus.com/bid/9895 | vdb entry exploit broken link third party advisory |