Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin access by modifying cookies and performing "certain consecutive actions," possibly due to a cross-site request forgery (CSRF) vulnerability.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www.attrition.org/pipermail/vim/2007-March/001446.html | mailing list |
http://www.web-app.org/cgi-bin/index.cgi?action=downloadinfo&cat=crip&id=2 | patch |
http://osvdb.org/33273 | vdb entry |
http://secunia.com/advisories/24540 | third party advisory vendor advisory |
http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=259 | |
http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=256 |