Lucene search

K
cve[email protected]CVE-2012-2930
HistoryApr 24, 2015 - 2:59 p.m.

CVE-2012-2930

2015-04-2414:59:01
CWE-352
web.nvd.nist.gov
18
csrf
tinywebgallery
twg
vulnerability
admin authentication
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.7%

Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an adduser action to admin/index.php or (2) conduct static PHP code injection attacks in .htusers.php via the user parameter to admin/index.php.

Affected configurations

NVD
Node
tinywebgallerytinywebgalleryRange1.8.6

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.7%