Back to search
CVE-2017-9810
Published: Jul 17, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20170628 [CORE-2017-0003] - Kaspersky Anti-Virus File Server Multiple Vulnerabilities
mailing-list
x_refsource_FULLDISC
99330
vdb-entry
x_refsource_BID
1038798
vdb-entry
x_refsource_SECTRACK
42269
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now