6.8
CVSSv2

CVE-2012-1216

Published: 21/02/2012 Updated: 24/02/2012
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in PBBoard 2.1.4 allow remote malicious users to hijack the authentication of administrators for requests that (1) upload a file via an add action or (2) change the contents of a file via a dit action.

Vulnerable Product Search on Vulmon Subscribe to Product

pbboard pbboard 2.1.4

Exploits

This Metasploit module exploits multiple cross site request forgery (CSRF) vulnerabilities in adminphp in PBBoard 214 to allow for arbitrary file upload / command execution ...
PBBoard version 214 suffers from improper authentication, improper access control, and remote SQL injection vulnerabilities ...