Intelligence Center » Browse All Vulnerabilities » CVE-2012-1900
Overview |
|
Vulnerability Score | ![]() |
CVE Id | CVE-2012-1900 |
Last Modified | 08 Nov 2012 12:00:00 |
Published | 22 Oct 2012 07:55:05 |
Confidentiality Impact | ![]() |
Integrity Impact | ![]() |
Availability Impact | ![]() |
Access Vector | NETWORK |
Access Complexity | MEDIUM |
Authentication | NONE |

CVE-2012-1900
Summary
Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary web pages via a showcats action.
Vulnerable Systems
Application
Razorcms 0.2
Razorcms 0.3
Razorcms 0.4
Razorcms 1.0
Razorcms 1.1
Razorcms 1.2
Razorcms 1.2.1
References
XF - razorcms-deletewebpage-csrf(73902)
EXPLOIT-DB - 18575
MISC - http://packetstormsecurity.org/files/110593/RazorCMS-1.2.1-STABLE-Cross-Site-Request-Forgery.html
Last Updated: 27 May 2016 11:01:14