Back to search
CVE-2015-4119
Published: Jun 15, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) administrators for requests that create an administrator account via a request to admin/users_edit.php or (2) arbitrary users for requests that conduct SQL injection attacks via the server parameter to monitor/show_sys_state.php.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20150610 Multiple Vulnerabilities in ISPConfig
mailing-list
x_refsource_BUGTRAQ
http://bugtracker.ispconfig.org/index.php?do=details&task_id=3898
x_refsource_CONFIRM
75126
vdb-entry
x_refsource_BID
37259
exploit
x_refsource_EXPLOIT-DB
https://www.htbridge.com/advisory/HTB23260
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now