6.8
CVSSv2

CVE-2015-4119

Published: 15/06/2015 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig prior to 3.0.5.4p7 allow remote malicious users to hijack the authentication of (1) administrators for requests that create an administrator account via a request to admin/users_edit.php or (2) arbitrary users for requests that conduct SQL injection attacks via the server parameter to monitor/show_sys_state.php.

Vulnerable Product Search on Vulmon Subscribe to Product

ispconfig ispconfig

Exploits

Advisory ID: HTB23260 Product: ISPConfig Vendor: wwwispconfigorg Vulnerable Version(s): 3054p6 and probably prior Tested Version: 3054p6 Advisory Publication: May 20, 2015 [without technical details] Vendor Notification: May 20, 2015 Vendor Patch: June 4, 2015 Public Disclosure: June 10, 2015 Vulnerability Type: SQL Injection ...
ISPConfig version 3054p6 suffers from cross site request forgery and remote SQL injection vulnerabilities ...