CVE-2016-4315
MEDIUMWSO2 Carbon 4.4.5 - Cross-Site Request Forgery via Server Shutdown Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-4315. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in WSO2 Carbon v4.4.5, allowing an attacker to trick a privileged user into shutting down the server via a malicious link. The exploit leverages the lack of CSRF protection in the `proxy_ajaxprocessor.jsp` endpoint.
Description
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in WSO2 Carbon v4.4.5, allowing an attacker to trick a privileged user into shutting down the server via a malicious link. The exploit leverages the lack of CSRF protection in the `proxy_ajaxprocessor.jsp` endpoint.
References (6)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H