Lucene search

K
cveMitreCVE-2011-5306
HistoryJan 01, 2015 - 11:59 a.m.

CVE-2011-5306

2015-01-0111:59:12
CWE-352
mitre
web.nvd.nist.gov
24
cve
2011
5306
csrf
vulnerability
cosmoshop
epro
remote attackers
hijack
authentication
administrators
modify settings
setup action

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.005

Percentile

77.2%

Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/setup_edit.cgi in CosmoShop ePRO 10.05.00 allows remote attackers to hijack the authentication of administrators for requests that modify settings via a setup action.

Affected configurations

Nvd
Node
zaunz_gmbhcosmoshopMatch10.05.00epro
VendorProductVersionCPE
zaunz_gmbhcosmoshop10.05.00cpe:2.3:a:zaunz_gmbh:cosmoshop:10.05.00:*:*:*:epro:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.005

Percentile

77.2%

Related for CVE-2011-5306