CVE-2012-4431
Apache Tomcat 6.x < 6.0.36 and 7.x < 7.0.32 - CSRF Protection Bypass via Sessionless Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-4431. PoCs published by imjdl.
AI-analyzed exploit summary The repository appears to be a partial or mislabeled Apache Tomcat distribution without any exploit code or proof-of-concept for CVE-2012-4431. It lacks any offensive techniques or vulnerability-specific payloads.
Description
org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
Exploits (1)
The repository appears to be a partial or mislabeled Apache Tomcat distribution without any exploit code or proof-of-concept for CVE-2012-4431. It lacks any offensive techniques or vulnerability-specific payloads.