6.8
CVSSv2

CVE-2015-6827

Published: 11/09/2015 Updated: 22/12/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote malicious users to hijack the authentication of users for requests that change a password via a request to signup.php.

Vulnerable Product Search on Vulmon Subscribe to Product

auto-exchanger auto-exchanger 5.1.0

Exploits

<!-- # Exploit Title: [Auto-exchanger version 510 Xsrf] # Date: [2015/06/05] # Exploit Author: [Aryan Bayaninejad] # Linkedin : [wwwlinkedincom/profile/view?id=276969082] # Vendor Homepage: [wwwauto-exchangercom] # Version: [Version 510] # Demo : wwwfarhadexchangecom # CVE : [CVE-2015-6827] ------------------------------------ ...
Autoexchanger version 510 suffers from a cross site request forgery vulnerability ...