6.8
CVSSv2

CVE-2010-3024

Published: 16/08/2010 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in user/main/update_user in DiamondList 0.1.6, and possibly earlier, allow remote malicious users to hijack the authentication of administrators for requests that (1) change the administrative password or (2) change the site's configuration.

Vulnerable Product Search on Vulmon Subscribe to Product

hulihanapplications diamondlist 0.1.6

Exploits

Vulnerability ID: HTB22517 Reference: wwwhtbridgech/advisory/xsrf_csrf_in_diamondlisthtml Product: DiamondList Vendor: Hulihan Applications ( hulihanapplicationscom/projects/diamondlist ) Vulnerable Version: 016 and Probably Prior Versions Vendor Notification: 22 July 2010 Vulnerability Type: CSRF (Cross-Site Request Forgery) St ...