6.8
CVSSv2

CVE-2015-6493

Published: 28/10/2015 Updated: 28/10/2015
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x up to and including 2.6.0 build 430 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

infinite automation systems mango automation 2.5.0

infinite automation systems mango automation 2.6.0

infinite automation systems mango automation 2.5.5

Exploits

Mango Automation 260 CSRF File Upload And Arbitrary JSP Code Execution Vendor: Infinite Automation Systems Inc Product web page: wwwinfiniteautomationcom/ Affected version: 252 and 260 beta (build 327) Summary: Mango Automation is a flexible SCADA, HMI And Automation software application that allows you to view, log, graph, anima ...