6.8
CVSSv2

CVE-2011-4837

Published: 15/12/2011 Updated: 15/12/2011
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote malicious users to hijack the authentication of admins for requests that execute arbitrary programs.

Vulnerable Product Search on Vulmon Subscribe to Product

homeseer homeseer hs2 2.5.0.20

Exploits

# HomeSeer Home Automation Software Multiple Web Vulnerabilities (0day) # Date: 3/6/12 # Author: Silent_Dream # Software Link: wwwhomeseercom/pub/setuphs2_5_0_49exe # Version: 25049 # Tested on: Win XP # CERT VU#796883: wwwkbcertorg/vuls/id/796883 #Note: This affects both HomeSeer HS2 and HomeSeer PRO #Previously reported ...