VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-2039
gpeasy_cms: Cross-site request forgery (CSRF) vulnerability in ...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2039

Original

Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an Admin_Users action to index.php. NOTE: some of these details are obtained from third party information.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-05-25
Source Information Category:
Advisory, Alert
Last Updated:
2010-05-26




Affected Product Tags
cpe:/a:gpeasy:gpeasy_cms:1.5
cpe:/a:gpeasy:gpeasy_cms:1.5:rc2
cpe:/a:gpeasy:gpeasy_cms:1.5:rc3
cpe:/a:gpeasy:gpeasy_cms:1.5:rc4
cpe:/a:gpeasy:gpeasy_cms:1.6
cpe:/a:gpeasy:gpeasy_cms:1.6.1
cpe:/a:gpeasy:gpeasy_cms:1.6.2 and previous versions
cpe:/a:gpeasy:gpeasy_cms:1.6.3
cpe:/a:gpeasy:gpeasy_cms:1.6:rc1
cpe:/a:gpeasy:gpeasy_cms:1.6:rc2
cpe:/a:gpeasy:gpeasy_cms:1.6:rc3
cpe:/a:gpeasy:gpeasy_cms:1.6:rc4
cpe:/a:gpeasy:gpeasy_cms:1.6:rc5
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

Alternatives




References
MISC http://www.exploit-db.com/exploits/12441




MISC http://packetstormsecurity.org/1004-exploits/gpeasy-xsrf.txt




OSVDB 64130




SECUNIA 39643




VUPEN ADV-2010-1030




Vulnerability Type Cross-Site Request Forgery (CSRF) (CWE-352)




XF gpeasy-admin-interface-csrf(58214)





Copyright © 2010 JPCERT/CC All Rights Reserved.