Back to search
CVE-2017-11193
Published: Jul 12, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute, traceroute6, nslookup, arp, and Portprobe. These functions do not have any protections against CSRF. That can allow an attacker to run these commands against any IP if they can get an admin to visit their malicious CSRF page.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
99621
vdb-entry
x_refsource_BID
https://twitter.com/sxcurity/status/884556905145937921
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now