Cross-site request forgery (CSRF) vulnerability in blocks_edit_do.php in sBlog 0.7.3 Beta allows remote attackers to change arbitrary blocks as administrators.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://securityreason.com/securityalert/3341 | third party advisory |
http://0x90.com.ar/Advisory/20071031.txt | |
http://secunia.com/advisories/27485 | third party advisory |
http://www.securityfocus.com/archive/1/483108/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38216 | vdb entry |