5.1
CVSSv2

CVE-2013-0214

Published: 02/02/2013 Updated: 30/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x prior to 3.5.21, 3.6.x prior to 3.6.12, and 4.x prior to 4.0.2 allows remote malicious users to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba 3.6.5

samba samba 3.6.6

samba samba 3.6.1

samba samba 3.6.2

samba samba 3.6.9

samba samba 3.6.10

samba samba 3.6.3

samba samba 3.6.4

samba samba 3.6.11

samba samba 3.6.0

samba samba 3.6.7

samba samba 3.6.8

samba samba 4.0.0

samba samba 4.0.1

samba samba 3.5.14

samba samba 3.5.13

samba samba 3.5.6

samba samba 3.5.5

samba samba 3.4.15

samba samba 3.4.14

samba samba 3.4.7

samba samba 3.4.6

samba samba 3.3.9

samba samba 3.5.18

samba samba 3.5.17

samba samba 3.5.10

samba samba 3.5.9

samba samba 3.5.2

samba samba 3.5.1

samba samba 3.4.11

samba samba 3.4.10

samba samba 3.4.3

samba samba 3.4.2

samba samba 3.3.0

samba samba 3.3.6

samba samba 3.3.15

samba samba 3.3.11

samba samba 3.3.5

samba samba 3.2.6

samba samba 3.2.5

samba samba 3.5.16

samba samba 3.5.15

samba samba 3.5.8

samba samba 3.5.7

samba samba 3.5.0

samba samba 3.4.17

samba samba 3.4.16

samba samba 3.4.9

samba samba 3.4.8

samba samba 3.4.1

samba samba 3.4.0

samba samba 3.3.16

samba samba 3.3.12

samba samba 3.3.4

samba samba 3.3.3

samba samba 3.2.4

samba samba 3.2.3

samba samba 3.2.12

samba samba 3.1.0

samba samba 3.0.14

samba samba 3.0.29

samba samba 3.0.0

samba samba 3.0.1

samba samba 3.0.23b

samba samba 3.0.23c

samba samba 3.0.20b

samba samba 3.0.21

samba samba 3.0.7

samba samba 3.0.6

samba samba 3.0.25a

samba samba 3.0.4

samba samba 3.0.23

samba samba 3.0.30

samba samba 3.0.26

samba samba 3.0.20

samba samba 3.0.25

samba samba 3.2.10

samba samba 3.2.11

samba samba 3.0.36

samba samba 3.0.14a

samba samba 3.0.2

samba samba 3.0.19

samba samba 3.0.23a

samba samba 3.0.20a

samba samba 3.0.9

samba samba 3.0.8

samba samba 3.0.34

samba samba 3.0.26a

samba samba 3.3.10

samba samba 3.3.13

samba samba 3.3.14

samba samba 3.2.0

samba samba 3.2.14

samba samba 3.2.7

samba samba 3.2.2

samba samba 3.0.28

samba samba 3.0.37

samba samba 3.0.16

samba samba 3.0.15

samba samba 3.0.11

samba samba 3.0.23d

samba samba 3.0.24

samba samba 3.0.21a

samba samba 3.0.21b

samba samba 3.0.2a

samba samba 3.0.25b

samba samba 3.0.3

samba samba 3.0.32

samba samba 3.0.33

samba samba 3.5.20

samba samba 3.5.19

samba samba 3.5.12

samba samba 3.5.11

samba samba 3.5.4

samba samba 3.5.3

samba samba 3.4.13

samba samba 3.4.12

samba samba 3.4.5

samba samba 3.4.4

samba samba 3.3.7

samba samba 3.3.8

samba samba 3.3.2

samba samba 3.3.1

samba samba 3.2.15

samba samba 3.2.13

samba samba 3.2.9

samba samba 3.2.1

samba samba 3.2.8

samba samba 3.0.27

samba samba 3.0.35

samba samba 3.0.18

samba samba 3.0.17

samba samba 3.0.10

samba samba 3.0.13

samba samba 3.0.12

samba samba 3.0.21c

samba samba 3.0.22

samba samba 3.0.5

samba samba 3.0.25c

samba samba 3.0.31

Vendor Advisories

Several security issues were fixed in Samba ...
Synopsis Moderate: samba3x security and bug fix update Type/Severity Security Advisory: Moderate Topic Updated samba3x packages that fix multiple security issues and several bugsare now available for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having moderatesecuri ...
Synopsis Moderate: samba security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated samba packages that fix three security issues, several bugs, andadd one enhancement are now available for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this up ...
Jann Horn had reported two vulnerabilities in Samba, a popular cross-platform network file and printer sharing suite In particular, these vulnerabilities affect to SWAT, the Samba Web Administration Tool CVE-2013-0213: Clickjacking issue in SWAT An attacker can integrate a SWAT page into a malicious web page via a frame or iframe and t ...