vendor:
FTGate 2009
by:
hyp3rlinx
N/A
CVSS
N/A
Cross site request forgery (CSRF)
Unknown
CWE
Product Name: FTGate 2009
Affected Version From: FTGate 2009 SR3 May 13 2010 Build 6.4.00
Affected Version To: FTGate 2009 SR3 May 13 2010 Build 6.4.00
Patch Exists: NO
Related CWE:
CPE: ftgate:ftgate:2009:6.4.00
Platforms Tested:
2009
FTGate 2009 CSRF Vulnerability
Multiple CSRF vectors exist within FTGate 2009 that allow us to add arbitrary remote domains, disable antivirus scanning for various Email file attachment types, and finally change settings to have archived server logs sent to our remote attacker controlled server for safe keeping.
Mitigation:
No known mitigation or remediation for this vulnerability.