CVE Database
/

CVE-2011-2522

Back to search

CVE-2011-2522

Published: Jul 29, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.

VendorProductVersions

n/a

n/a

affected
n/a

References

MDVSA-2011:121
vendor-advisory
x_refsource_MANDRIVA
74071
vdb-entry
x_refsource_OSVDB
HPSBNS02701
vendor-advisory
x_refsource_HP
SSRT100664
vendor-advisory
x_refsource_HP
HPSBUX02768
vendor-advisory
x_refsource_HP
1025852
vdb-entry
x_refsource_SECTRACK
DSA-2290
vendor-advisory
x_refsource_DEBIAN
45393
third-party-advisory
x_refsource_SECUNIA
45496
third-party-advisory
x_refsource_SECUNIA
45488
third-party-advisory
x_refsource_SECUNIA
SSRT100598
vendor-advisory
x_refsource_HP
17577
exploit
x_refsource_EXPLOIT-DB
8317
third-party-advisory
x_refsource_SREASON
JVN#29529126
third-party-advisory
x_refsource_JVN
USN-1182-1
vendor-advisory
x_refsource_UBUNTU
48899
vdb-entry
x_refsource_BID
samba-swat-csrf(68843)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now