6.8
CVSSv2

CVE-2013-7057

Published: 04/11/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and previous versions allows remote malicious users to hijack the authentication of unspecified users for requests that upload arbitrary files via a crafted request to api/v1.0/files/.

Vulnerable Product Search on Vulmon Subscribe to Product

axway securetransport

Exploits

<!-- # Exploit Title: Axway Secure Transport 51 SP2 Arbitary File Upload via CSRF # Exploit author: Emmanuel Law # Public Disclosure Date : 20/10/14 # Vendor homepage: wwwaxwaycom # Affected Software version: Axway Secure Transport 521 SP2 and possibly earlier versions # CVE: CVE-2013-7057 Software Description: =================== ...