vendor:
Tinypug
by:
AmnPardaz Security Research Team
8,8
CVSS
HIGH
CSRF and Stored XSS
352, 79
CWE
Product Name: Tinypug
Affected Version From: 0.9.5
Affected Version To: 0.9.5
Patch Exists: NO
Related CWE: N/A
CPE: //a:tinypug:tinypug:0.9.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Tinypug Multiple Vulnerabilities
The password changing page of Tinypug is vulnerable to CSRF attack which can be used to change the password of the victim. The comment page is vulnerable to Stored XSS attack. But comments will be published only after administrator confirmation. However this XSS vulnerablity can be used in conjunction with the more serious security whole (CSRF) in order to change administrator's password.
Mitigation:
N/A