6.8
CVSSv2

CVE-2010-1611

Published: 29/04/2010 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in AlegroCart 1.1 allows remote malicious users to hijack the authentication of the administrator for requests that reset the administrator password via a POST to admin/ with an update action.

Vulnerable Product Search on Vulmon Subscribe to Product

alegrocart alegrocart 1.1

Exploits

[#]----------------------------------------------------------------[#] # # [+] Home Of AlegroCart v11 - [ Xsrf] Change Administrator Password # # // Author Info # [x] Author: TheMorpheus # [x] Contact: fats0L@windowslivecom<mailto:fats0L@windowslivecom> # [x] Thanks: Türksecİnfo ~ Nd And Tg Tayfa :P # [x] Date : 01022010 # [# ...