CVE Database
/

CVE-2011-0545

Back to search

CVE-2011-0545

Published: Mar 28, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts, and possibly have unspecified other impact, via the userRole parameter.

VendorProductVersions

n/a

n/a

affected
n/a

References

43820
third-party-advisory
x_refsource_SECUNIA
symantec-lua-gui-csrf(66213)
vdb-entry
x_refsource_XF
71261
vdb-entry
x_refsource_OSVDB
17026
exploit
x_refsource_EXPLOIT-DB
8160
third-party-advisory
x_refsource_SREASON
ADV-2011-0727
vdb-entry
x_refsource_VUPEN
1025242
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now