Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences, as demonstrated by a crafted nickname field to vserver/apply.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2011-10-06 19:51
Updated : 2011-11-23 19:58
NVD link : CVE-2011-2191
Mitre link : CVE-2011-2191
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
cherokee-project
- cherokee