6.8
CVSSv2

CVE-2012-4325

Published: 14/08/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and previous versions allows remote malicious users to hijack the authentication of administrators for requests that add administrator accounts.

Vulnerable Product Search on Vulmon Subscribe to Product

utopiasoftware news pro

Exploits

# Exploit Title: Utopia News Pro 140 <= CSRF Add Admin Vulnerability # Date: 7/4/2012 # Author: DrNaNo # Software Link: wwwutopiasoftwarenet/newspro/dlphp?filename=newspro140bzip&mirror=1 # Version: 140 # Tested on: Linux-Red-Hat # Google Dork: Powered By Utopia News Pro 140 # ############################################### ...