vendor:
WPN-XM Serverstack for Windows
by:
hyp3rlinx
7.5
CVSS
HIGH
CSRF
352
CWE
Product Name: WPN-XM Serverstack for Windows
Affected Version From: 2000.8.6
Affected Version To: 2000.8.6
Patch Exists: NO
Related CWE:
CPE: a:wpn-xm:wpn-xm_serverstack_for_windows:0.8.6
Platforms Tested: Windows
CSRF – MySQL / PHP.INI Hijacking
WPN-XMs webinterface is prone to multiple CSRF entry points allowing remote attackers to compromise an authenticated user if they visit a malicious webpage or click an attacker supplied link. Attackers can modify the 'PHP.INI' file to change arbitrary PHPs settings like enable 'allow_url_include' or changing the default MySQL username & password settings etc...
Mitigation:
Implement CSRF protection mechanisms in the webinterface to prevent unauthorized modification of PHP.INI settings.