CVE Database
/

CVE-2007-3489

Back to search

CVE-2007-3489

Published: Jun 29, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as demonstrated by a request with the swuuser and swupass parameters, which adds an administrator account. NOTE: the CSRF attack has no timing window because there is no logout capability in the management interface.

VendorProductVersions

n/a

n/a

affected
n/a

References

37645
vdb-entry
x_refsource_OSVDB
ADV-2007-2363
vdb-entry
x_refsource_VUPEN
25853
third-party-advisory
x_refsource_SECUNIA
2848
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now