4.3
CVSSv2

CVE-2011-0642

Published: 25/01/2011 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote malicious users to hijack the authentication of administrators for requests that create new users via the options action. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

network-13 n-13 news 3.7

network-13 n-13 news 4.0

network-13 n-13 news 3.4

Exploits

======================================================== N-13 News 34 Remote Admin Add CSRF Exploit ======================================================== #Title: N-13 News 34 Remote Admin Add CSRF Exploit #Author : anT!-Tr0J4n #Email : D3v-PoinT[at]hotmail[d0t]com & C1EH[at]Hotmail[d0t]com #Greetz : Dev-PoinTcom ...