Record summary

CVE-2012-2316 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.

Description

Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary code via the script parameter to admin/scripting.jsp.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBOpenKM Document Management System 5.1.7 - Command ExecutionExploitDB exploitby Cyrill BrunschwilerNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

11