Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-6479

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2008-6479
Last Modified 17 Mar 2009 12:00:00
Published 16 Mar 2009 03:30:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-6479

Summary

Cross-site request forgery (CSRF) vulnerability in the "change password" feature in the VZPP web interface for Parallels Virtuozzo 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote attackers to modify the password via a link or IMG tag to vz/cp/pwd.

Vulnerable Systems

Application

  • Parallels Virtuozzo 25.4swsoft


References

XF - virtuozzo-change-password-csrf(41638)

BID - 28593

BUGTRAQ - 20080402 Parallels virtuozzo's VZPP multiple csrf vulnerabilities

SECUNIA - 29675

OSVDB - 44394


Last Updated: 27 May 2016 10:49:12