vendor:
NinkoBB Forum Script
by:
Canberk BOLAT
7,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: NinkoBB Forum Script
Affected Version From: 1.3RC5
Affected Version To: Possible all versions
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
NinkoBB CSRF Vulnerability
If administrator of the board browse PoC attacker can gain privilege access.
Mitigation:
Implementing CSRF protection mechanisms such as synchronizer tokens, or using a framework that provides CSRF protection.