CVE-2010-5285 Information

Description

Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrators for requests that add administrative users via the edituser action.

Reference

http://packetstormsecurity.org/1010-exploits/collabtive-xssxsrf.txt http://secunia.com/advisories/41805 http://www.anatoliasecurity.com/adv/as-adv-2010-003.txt http://www.exploit-db.com/exploits/15240 http://www.securityfocus.com/bid/44050

Share on: