Cross-site request forgery (CSRF) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to change the admin password via (1) a certain HTML form that is posted automatically by JavaScript or (2) a news post.
Link | Tags |
---|---|
http://osvdb.org/38617 | vdb entry |
http://securityreason.com/securityalert/2829 | third party advisory |
http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/064051.html | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34893 | vdb entry |