6
CVSSv2

CVE-2010-0540

Published: 17/06/2010 Updated: 19/09/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS prior to 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 prior to 10.6.4, and other platforms, allows remote malicious users to hijack the authentication of administrators for requests that change settings.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.6.1

apple mac os x server 10.6.0

apple mac os x 10.5.8

apple mac os x 10.6.0

apple mac os x server 10.6.2

apple mac os x server 10.6.3

apple mac os x 10.6.3

apple mac os x server 10.5.8

apple mac os x server 10.6.1

apple mac os x 10.6.2

Vendor Advisories

Adrian Pastor and Tim Starling discovered that the CUPS web interface incorrectly protected against cross-site request forgery (CSRF) attacks If an authenticated user were tricked into visiting a malicious website while logged into CUPS, a remote attacker could modify the CUPS configuration and possibly steal confidential data (CVE-2010-0540) ...
Several vulnerabilities have been discovered in the Common UNIX Printing System: CVE-2008-5183 A null pointer dereference in RSS job completion notifications could lead to denial of service CVE-2009-3553 It was discovered that incorrect file descriptor handling could lead to denial of service CVE-2010-0540 A cross-site request for ...