LWN.net Logo

extplorer: cross-site request forgery

Package(s):extplorer CVE #(s):CVE-2012-3362
Created:July 13, 2012 Updated:July 18, 2012
Description: From the Debian advisory:

John Leitch has discovered a vulnerability in eXtplorer, a very feature rich web server file manager, which can be exploited by malicious people to conduct cross-site request forgery attacks.

The vulnerability allows users to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited for example, to create an administrative user account by tricking an logged administrator to visiting an attacker-defined web link.

Alerts:
Debian DSA-2510-1 2012-07-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds