Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2010-3305 | third party advisory |
https://access.redhat.com/security/cve/cve-2010-3305 | broken link |
https://www.exploit-db.com/exploits/15014 | exploit vdb entry third party advisory |
https://www.openwall.com/lists/oss-security/2010/09/17/7 | third party advisory mailing list |