vendor:
Chipmunk Board Script
by:
Milos Zivanovic
8.8
CVSS
HIGH
Cross Site Request Forgery
352
CWE
Product Name: Chipmunk Board Script
Affected Version From: 1.X
Affected Version To: 1.X
Patch Exists: NO
Related CWE: N/A
CPE: chipmunk-scripts.com/chipmunkcms/chipmunkcms.zip
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Chipmunk Board Script 1.x Multiple XSRF Vulnerabilities
This board script doesn't have any XSRF protection thus allowing us to do many things we shouldn't. This exploit will change this info for every user that opens it and is logged in.
Mitigation:
Implement XSRF protection in the application.