355
VMScore

CVE-2016-4315

Published: 17/02/2017 Updated: 09/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.7 | Impact Score: 3.6 | Exploitability Score: 2.1
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote malicious users to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.

Vulnerable Product Search on Vulmon Subscribe to Product

wso2 carbon 4.4.5

Exploits

[+] Credits: John Page aka HYP3RLINX [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/WSO2-CARBON-v445-CSRF-DOStxt [+] ISR: ApparitionSec Vendor: ============ wwwwso2com Product: ================== Ws02Carbon v445 WSO2 Carbon is the core platform on which WSO2 middleware products are built ...
WSO2 Carbon version 445 suffers from a cross site request forgery vulnerability that can trigger a denial of service condition ...