Cross-site request forgery (CSRF) vulnerability in the administrative interface for the TeraStation HD-HTGL firmware 2.05 beta 1 and earlier allows remote attackers to modify configurations or delete arbitrary data via unspecified vectors.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://secunia.com/advisories/22248 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/29338 | vdb entry third party advisory |
http://jvn.jp/jp/JVN%2393484133/index.html | third party advisory |
http://www.vupen.com/english/advisories/2006/3891 | vdb entry broken link |