Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www.gulftech.org/?node=research&article_id=00076-05172005 | broken link |
http://www.securityfocus.com/archive/1/398457/2005-05-15/2005-05-21/0 | patch mailing list vdb entry exploit vendor advisory broken link third party advisory |