Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2) admin/news.php, (3) admin/user.php, (4) admin/images.php, (5) admin/page.php, or (6) admin/forums.php.
Link | Tags |
---|---|
http://www.phpx.org/project.php?action=view&project_id=1 | url repurposed patch |
http://www.osvdb.org/5909 | vdb entry |
http://securitytracker.com/id?1010061 | vdb entry |
http://www.osvdb.org/5908 | vdb entry |
http://www.osvdb.org/5911 | vdb entry |
http://www.securityfocus.com/bid/10284 | exploit vdb entry patch |
http://www.osvdb.org/5910 | vdb entry |
http://www.securityfocus.com/archive/1/362230 | mailing list exploit vendor advisory |
http://secunia.com/advisories/11554 | third party advisory |
http://www.osvdb.org/5907 | vdb entry |