[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

OSSIM 2.2.1 CSRF Vulnerability

Author
Nicolas Gregoire
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11573
Category
web applications
Date add
02-04-2010
Platform
php
==============================
OSSIM 2.2.1 CSRF Vulnerability
==============================

CSRF Vulnerability in OSSIM 2.2.1

Discovered by: CONIX Security (www.conix.fr)
Public Release Date: 4/01/2010
Vendor: Alienvault (www.alienvault.com)

============= Technical Details =============

The page /ossim/control_panel/alarm_console.php is vulnerable to a CSRF vulnerability. An attacker can send a malicious link to an authorized OSSIM user and, by social engineering, provoke the deletion of all the alarms:

/ossim/control_panel/alarm_console.php?delete_backlog=all


Nicolas Grandjean



#  0day.today [2024-07-16]  #