OSVDB ID: 66388

Title: XMB Admin Password Manipulation CSRF

Info

Disclosure

Jul 15, 2010

Discovery

Unknown

Dates

Exploit

Jul 15, 2010

Solution

Feb 06, 2011

Description

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public
Disclosure: Uncoordinated Disclosure
OSVDB: Web Related

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, The XMB Group has released a patch to address this vulnerability. Check the vendor advisory or solution in the references section.

Products

The XMB Group

XMB Forum

1.9.11
1.6
1.9.1
1.8
1.5
1.9.3
1.9.5
1.9.8 SP1
1.9.8 SP2

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/66388