Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a saveNewUser action.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www.osvdb.org/69083 | vdb entry |
http://www.exploit-db.com/exploits/15473 | exploit |
http://www.securityfocus.com/archive/1/514688/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/44740 | vdb entry exploit |
http://security.fatihkilic.de/advisory/fkilic-sa-2010-ibm-omnifind.txt | exploit |
http://www.vupen.com/english/advisories/2010/2933 | vdb entry vendor advisory |