6.8
CVSSv2

CVE-2012-2602

Published: 12/08/2012 Updated: 13/08/2012
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) prior to 10.3.1 allow remote malicious users to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to Admin/Accounts/Add/OrionAccount.aspx or (2) modify account privileges via a ynAdminRights action to Admin/Accounts/EditAccount.aspx.

Vulnerable Product Search on Vulmon Subscribe to Product

solarwinds orion network performance monitor 10.1.13.0

solarwinds orion network performance monitor

Exploits

/* ###################################################################################### # Exploit Title: SolarWinds Orion Network Performance Monitor 1022 Multiple Vulnerabilities # Date: Jul 21 2012 # Author: muts # Version: SolarWinds Orion Network Performance Monitor 1022 # Vendor URL: wwwsolarwindscom/ ########################### ...