6.8
CVSSv2

CVE-2009-4120

Published: 01/12/2009 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote malicious users to hijack the authentication of the administrator for requests that (1) delete orders via an orders-delete action to admin.php, and possibly (2) delete products or (3) delete pages via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

opensolution quick.cart 3.4

Exploits

Systems Affected: QuickCart 34 (other versions untested), QuickCMS 24 (other versions untested) Severity: Medium Vendor: opensolutionorg/ Author: Alice Kaerast 0 Timeline 25-10-2009 Vulnerability discovered 26-10-2009 Vendor contacted 23-11-2009 No response from vendor, report published 1 Background QuickCart is a "freeware, simple ...
source: wwwsecurityfocuscom/bid/37115/info QuickCart and QuickCMS are prone to a cross-site request-forgery vulnerability because the applications allow users to bypass certain security checks Exploiting this issue may allow a remote attacker to perform certain administrative actions, gain unauthorized access to an affected applicatio ...