CVE-2017-12970
HIGHApache2Triad 1.5.4 - Cross-Site Request Forgery in User Account Management
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-12970. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates session fixation, CSRF, and persistent XSS vulnerabilities in Apache2Triad v1.5.4. It includes PoC code for each CVE, showing how an attacker can hijack sessions, execute unauthorized actions, and inject malicious scripts.
Description
Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for requests that (1) add or (2) delete user accounts via a request to phpsftpd/users.php.
Exploits (1)
This exploit demonstrates session fixation, CSRF, and persistent XSS vulnerabilities in Apache2Triad v1.5.4. It includes PoC code for each CVE, showing how an attacker can hijack sessions, execute unauthorized actions, and inject malicious scripts.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H