CVE-2009-0468 Information

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown the server (2) send ping packets (3) enable network services (4) configure a proxy server and (5) modify other settings via parameters in the query string.

Reference

http://osvdb.org/51660 http://secunia.com/advisories/33739 http://www.securityfocus.com/bid/33523 https://www.exploit-db.com/exploits/7919

Share on: