6.8
CVSSv2

CVE-2014-6409

Published: 06/10/2014 Updated: 08/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and previous versions allows remote malicious users to hijack the authentication of administrators for requests that change user passwords via the fullname and password parameters to /admin/users/update.

Vulnerable Product Search on Vulmon Subscribe to Product

mmonit m\\/monit

Exploits

Vulnerability title: M/Monit CSRF Author: Dolev Farhi Contact: dolevf at openflare dot com @dolevff Application: M/Monit 322 Date: 1392014 Relevant CVEs: N/A Vulnerable version: <= 322 Fixed version: N/A 1 About the application ------------------------ Easy, proactive monitoring of Unix systems, network and cloud services Conduct au ...
M/Monit versions 322 and below suffer from multiple cross site request forgery vulnerabilities ...