6.8
CVSSv2

CVE-2017-12970

Published: 23/08/2017 Updated: 03/05/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote malicious users to hijack the authentication of authenticated users for requests that (1) add or (2) delete user accounts via a request to phpsftpd/users.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache2triad apache2triad 1.5.4

Exploits

[+] Credits: John Page AKA hyp3rlinx [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/APACHE2TRIAD-SERVER-STACK-v154-MULTIPLE-CVEtxt [+] ISR: ApparitionSec Vendor: =============== apache2triadnet sourceforgenet/projects/apache2triad/ Product: =========== Apache2Triad v15 ...
Apache2Triad version 154 suffers from session fixation, cross site request forgery, and cross site scripting vulnerabilities ...