47947Third-party advisory
http://secunia.com/advisories/47947 CVE-2012-1220
GAzie 5.20 - Cross-Site Request Forgery
Record summary
CVE-2012-1220 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Cross-site request forgery (CSRF) vulnerability in modules/config/admin_utente.php in GAzie 5.20 and earlier allows remote attackers to hijack the authentication of administrators for requests that change account information via an update action, as demonstrated by changing the password.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGAzie 5.20 - Cross-Site Request ForgeryExploitDB exploitby Giuseppe D'InvernoNot analyzed1 file
References
418464exploit
http://www.exploit-db.com/exploits/18464 gazie-adminutente-csrf(72991)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/72991 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-1220