Full Disclosure mailing list archives
cherokee server admin vulnerable to csrf
From: dave b <db.pub.mail () gmail com>
Date: Wed, 1 Jun 2011 19:07:16 +1000
Vendor response: "This isn't an issue." Problem: the cherokee server admin configuration web interface is vulnerable to csrf. Impact: if an admin is logged into the cherokee admin interface and visits a site which runs "bad tm scripts" cherokee can be reconfigured to run as $user and set log handlers(hooks) to execute arbitrary commands (on error and on access). _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- cherokee server admin vulnerable to csrf dave b (Jun 01)