Multiple cross-site request forgery (CSRF) vulnerabilities in Post Revolution 0.8.0c-2 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests to (1) ajax-weblog-guardar.php, (2) verpost.php, (3) comments.php, or (4) perfil.php.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/518205/100/0/threaded | mailing list |
http://osvdb.org/72641 | vdb entry |
http://javierb.com.ar/2011/06/01/postrev-vunls/ | |
http://secunia.com/advisories/44710 | third party advisory |
http://securityreason.com/securityalert/8270 | third party advisory |
http://postrev.com.ar/verpost.php?id_noticia=59 |