6.8
CVSSv2

CVE-2012-6508

Published: 24/01/2013 Updated: 29/01/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in NetArt Media Car Portal 3.0 allow remote malicious users to hijack the authentication of administrators for requests that (1) change arbitrary user passwords via a nouveau action in the security module to cars/ADMIN/index.php; (2) create a user or (3) create a sub user via a sub_accounts action in the home module to USERS/index.php; or (4) change profile information via an edit action in the profile module to USERS/index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

netartmedia car portal 3.0

Exploits

Title: ====== Car Portal CMS v30 - Multiple Web Vulnerabilities Date: ===== 2012-04-24 References: =========== wwwvulnerability-labcom/get_contentphp?id=502 VL-ID: ===== 502 Introduction: ============= Car Portal is a php software product for running auto classifieds websites It provides functionality for the private sellers to sig ...