5.1
CVSSv2

CVE-2010-2282

Published: 15/06/2010 Updated: 17/06/2010
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in TomatoCMS 2.0.6 allows remote malicious users to hijack the authentication of administrators for requests that change the administrative password.

Vulnerable Product Search on Vulmon Subscribe to Product

tomatocms tomatocms 2.0.6

Exploits

<!--- Title: TomatoCMS 205 Multiple CSRF Vulnerabilities Author: 10n1z3d <10n1z3d[at]w[dot]cn> Date: Sun 11 Jul 2010 03:36:08 PM EEST Vendor: wwwtomatocmscom/ Download: None ---> -=[ CSRF PoC 1 - Change Administrator Password ]=- <html> <head> <title>TomatoCMS 2 ...