6.8
CVSSv2

CVE-2015-4659

Published: 18/06/2015 Updated: 07/12/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and previous versions allows remote malicious users to hijack the authentication of administrators for requests that change the administrator password via a config action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

labsmedia clickheat

Exploits

# Exploit Title: ClickHeat <114 Change Admin Password CSRF # Google Dork: allinurl:/clickheat/ # Date: 11-06-2015 # Exploit Author: David Shanahan (@CyberpunkSec) # Contact: twittercom/CyberpunkSec # Vendor Homepage: wwwlabsmediacom/clickheat/indexhtml # Software Link: sourceforgenet/projects/clickheat/files/clickhea ...