Record summary

CVE-2012-1058 has a selected CVSS score of 6.0; EIP currently links 1 catalogued exploit.

Description

Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an admin.newuser action to index.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBFlyspray 0.9.9.6 - Cross-Site Request ForgeryExploitDB exploitby Vaibhav GuptaNot analyzed1 file
ExploitDB

PoC details

References

6