6.8
CVSSv2

CVE-2012-4877

Published: 06/09/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 and previous versions allows remote malicious users to hijack the authentication of administrators for requests that add user accounts.

Vulnerable Product Search on Vulmon Subscribe to Product

flatnux flatnux

flatnux flatnux 2008-12-11

flatnux flatnux 2009-02-04

flatnux flatnux 2009-01-27

Exploits

source: wwwsecurityfocuscom/bid/52846/info Flatnux is prone to multiple security vulnerabilities: 1 An HTML-injection vulnerability 2 A cross-site request-forgery vulnerability 3 A directory-traversal vulnerability Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, ...