7.5
CVSSv2

CVE-2014-6607

Published: 06/10/2014 Updated: 07/10/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

M/Monit 3.3.2 and previous versions does not verify the original password before changing passwords, which allows remote malicious users to change the password of other users and gain privileges via the fullname and password parameters, a different vulnerability than CVE-2014-6409.

Vulnerable Product Search on Vulmon Subscribe to Product

mmonit m\\/monit

Exploits

Vulnerability title: M/Monit CSRF Author: Dolev Farhi Contact: dolevf at openflare dot com @dolevff Application: M/Monit 322 Date: 1392014 Relevant CVEs: N/A Vulnerable version: <= 322 Fixed version: N/A 1 About the application ------------------------ Easy, proactive monitoring of Unix systems, network and cloud services Conduct au ...
M/Monit versions 322 and below suffer from multiple cross site request forgery vulnerabilities ...