CVE-2014-7190
Openfiler 2.99.1 - Cross-Site Request Forgery via System Shutdown/Reboot
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-7190. PoCs published by Dolev Farhi.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Openfiler 2.99.1, allowing an attacker to reboot or shutdown the server via a crafted HTML form. The lack of session tokens enables unauthorized state-changing actions.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in Openfiler 2.99.1 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown or (2) reboot the server via a request to admin/system_shutdown.html.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in Openfiler 2.99.1, allowing an attacker to reboot or shutdown the server via a crafted HTML form. The lack of session tokens enables unauthorized state-changing actions.