Security Advisory

CVE-2012-2999

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-10-04 19:00:00
Last updated 2024-08-06 19:50:05
Assigner certcc
CVSS score not scored
State PUBLISHED

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in Cerberus FTP Server before 5.0.5.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user account or (2) reconfigure the state of the FTP service, as demonstrated by a request to usermanager/users/modify.