6
CVSSv2

CVE-2012-0829

Published: 14/02/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in Mibew Messenger 1.6.4 and previous versions allow remote malicious users to hijack the authentication of operators for requests that insert cross-site scripting (XSS) sequences via the (1) address or (2) threadid parameters to operator/ban.php; or (3) geolinkparams, (4) title, or (5) chattitle parameters to operator/settings.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mibew mibew messenger 1.6.1

mibew mibew messenger 1.6.0

mibew mibew messenger 1.0.10

mibew mibew messenger 1.0.9

mibew mibew messenger 1.6.3

mibew mibew messenger 1.6.2

mibew mibew messenger 1.4.1

mibew mibew messenger 1.4.0

mibew mibew messenger 1.5.2

mibew mibew messenger 1.5.1

mibew mibew messenger 1.0.8

mibew mibew messenger 1.0.7

mibew mibew messenger

mibew mibew messenger 1.5.0

mibew mibew messenger 1.4.2

mibew mibew messenger 1.0.6