vendor:
Parallels Virtuozzo Containers
by:
poplix papuasia.org
7.5
CVSS
HIGH
Cross-Site Request-Forgery
352
CWE
Product Name: Parallels Virtuozzo Containers
Affected Version From: Virtuozzo Containers 3.0.0-25.4.swsoft
Affected Version To: Virtuozzo Containers 3.0.0-25.4.swsoft
Patch Exists: YES
Related CWE: N/A
CPE: a:swsoft:parallels_virtuozzo_containers
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Parallels Virtuozzo Containers Cross-Site Request-Forgery Vulnerability
Parallels Virtuozzo Containers is prone to a cross-site request-forgery vulnerability. Exploiting the issue will allow a remote attacker to use a victim's currently active session to change the victim's password. Successful exploits will compromise affected computers.
Mitigation:
Ensure that the application is not vulnerable to Cross-Site Request Forgery attacks by implementing appropriate measures such as validating the origin of the request.