6.8
CVSSv2

CVE-2012-1416

Published: 08/10/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in SocialCMS 1.0.2 allow remote malicious users to hijack the authentication of administrators for requests that (1) add administrator accounts via a member_new action to my_admin/admin1_members.php or (2) modify the default site title via a save action to my_admin/admin1_configuration.php.

Vulnerable Product Search on Vulmon Subscribe to Product

socialcms socialcms 1.0.2

Exploits

+-------------------------------------------------------------------------+ # Exploit Title : Socialcms CSRF Vulnerability # Date : 16-02-2012 # Author : Ivano Binetti (ivanobinetticom) # Vendor site : socialcmscom # Software link : sourceforgenet/projects/socialcms/files/latest/download # Version : 1 ...
<!--- Title: socialcms102 Multiple CSRF Vulnerabilities Author: vir0e5 aka banditc0de <vir0e5@yahoocom> Date: Wed 20 april 2011 11:18:22 AM Vendor: wwwsocialcmscom Download: sourceforgenet/projects/socialcms/ ---> <!-- Create Admin User --> <body onload='documentcsrfsubmit()'> <for ...