CVE-2010-4750
BLOG:CMS 4.2.1.e - Cross-Site Request Forgery in admin/libs/ADMIN.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-4750. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in BLOG:CMS 4.2.1.e, including CSRF and XSS. It provides PoC code for CSRF attacks to modify user settings and XSS via unsanitized input in 'body', 'amount', and 'action' variables.
Description
Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allows remote attackers to hijack the authentication of administrators.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in BLOG:CMS 4.2.1.e, including CSRF and XSS. It provides PoC code for CSRF attacks to modify user settings and XSS via unsanitized input in 'body', 'amount', and 'action' variables.