6.8
CVSSv2

CVE-2010-3030

Published: 17/08/2010 Updated: 18/08/2010
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Tomaz Muraus Open Blog 1.2.1, and possibly earlier, allows remote malicious users to hijack the authentication of administrators for requests that change the administrative password. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

tomaz-muraus open blog 1.2.1

Exploits

Vulnerability ID: HTB22496 Reference: wwwhtbridgech/advisory/xsrf_csrf_in_open_bloghtml Product: Open Blog Vendor: Tomaž Muraus ( wwwopen-bloginfo/ ) Vulnerable Version: 121 and Probably Prior Versions Vendor Notification: 22 July 2010 Vulnerability Type: CSRF (Cross-Site Request Forgery) Status: Not Fixed, Vendor Alerted, A ...