Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-6478

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2008-6478
Last Modified 17 Mar 2009 12:00:00
Published 16 Mar 2009 03:30:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-6478

Summary

Cross-site request forgery (CSRF) vulnerability in the file manager in the VZPP web interface for Parallels Virtuozzo 365.6.swsoft (build 4.0.0-365.6.swsoft) and 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote attackers to create and delete arbitrary files as the administrator via a link or IMG tag to (1) create-file and (2) list-control in vz/cp/vzdir/infrman/envs/files/; or modify system configuration via the path parameter to vz/cp/vzdir/infrman/envs/files/index.

Vulnerable Systems

Application

  • Parallels Virtuozzo Containers 3.0.0-25.4.swsoft

  • Parallels Virtuozzo Containers 4.0.0-365.6.swsoft


References

XF - virtuozzo-file-manager-csrf(41640)

BID - 28589

BUGTRAQ - 20080402 Parallels virtuozzo's VZPP multiple csrf vulnerabilities

SECUNIA - 29675

OSVDB - 44395


Last Updated: 27 May 2016 10:49:12