6.8
CVSSv2

CVE-2011-0545

Published: 28/03/2011 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) prior to 2.3 allows remote malicious users to hijack the authentication of administrators for requests that create new administrative accounts, and possibly have unspecified other impact, via the userRole parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec liveupdate administrator 2.2.2.9

Exploits

source: wwwsecurityfocuscom/bid/46856/info Symantec LiveUpdate Administrator is prone to an HTML-injection vulnerability Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected application, potentially allowing the attacker to steal cookie-based authentication credentials or to control ...
Symantec LiveUpdate Administrator suffers from a cross site request forgery vulnerability Proof of concept is included ...