CVE-2010-3603 Information

Description

Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to hijack the authentication of administrators for requests that rename arbitrary files as demonstrated by causing the user.config file to be moved leading to a denial of service (service stop) and possibly the exposure of sensitive information.

Reference

http://osvdb.org/68060 http://packetstormsecurity.org/1009-advisories/moaub16-mojoportal.pdf http://packetstormsecurity.org/1009-exploits/moaub-mojoportal.txt http://secunia.com/advisories/41481 http://www.exploit-db.com/exploits/15018 http://www.mojoportal.com/mojoportal-2352-released.aspx https://exchange.xforce.ibmcloud.com/vulnerabilities/61834

Share on: