6.8
CVSSv2

CVE-2008-6478

Published: 16/03/2009 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the file manager in the VZPP web interface for Parallels Virtuozzo 365.6.swsoft (build 4.0.0-365.6.swsoft) and 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote malicious users to create and delete arbitrary files as the administrator via a link or IMG tag to (1) create-file and (2) list-control in vz/cp/vzdir/infrman/envs/files/; or modify system configuration via the path parameter to vz/cp/vzdir/infrman/envs/files/index.

Vulnerable Product Search on Vulmon Subscribe to Product

parallels virtuozzo containers 4.0.0-365.6.swsoft

parallels virtuozzo containers 3.0.0-25.4.swsoft

Exploits

source: wwwsecurityfocuscom/bid/28589/info Parallels Virtuozzo Containers is prone to a cross-site request-forgery vulnerability Exploiting the issue will allow a remote attacker to use a victim's currently active session to perform certain file-management actions with the privileges of the user running the application Successful explo ...