6.8
CVSSv2

CVE-2012-5326

Published: 08/10/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in admin/function.php in IDevSpot iSupport 1.x allows remote malicious users to hijack the authentication of administrators for requests that add administrator accounts via an administrators action.

Vulnerable Product Search on Vulmon Subscribe to Product

idevspot isupport 1.0

idevspot isupport 1.8

idevspot isupport 1.02

idevspot isupport 1.06

Exploits

#!/usr/bin/perl ######################################################################## # Title : iSupport v1x => Html Code injection to add admin # Author : Or4nGM4n # Version : 1x # Homepage : wwwidevspotcom/iSupportphp # Google Dork: "Powered by [ iSupport 18 ]" # Homepage : wwwidevspotcom/ # Thnks : # +--------- ...