Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1968.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2010/1792 | vdb entry vendor advisory |
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388 | vendor advisory |
http://securitytracker.com/id?1024186 | vdb entry |
http://secunia.com/advisories/40553 | third party advisory vendor advisory |