Cybertrion Systems

[2/5] ikiwiki Cross-Site Request Forgery Vulnerabilities

April 21st, 2008 by
[2/5] ikiwiki Cross-Site Request Forgery Vulnerabilities

:Some vulnerabilities have been reported in ikiwiki, which can be exploited by malicious people to conduct cross-site request forgery attacks.The vulnerabilities are caused due to the application allowing users to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited to e.g. change a user’s password and manipulate certain preferences or wiki pages.The vulnerabilities are reported in versions prior to 2.42.Solution:Update to version 2.42.http://ikiwiki.info/download/Provided and/or discovered by:Reported by the vendor.Original Advisory:http://ikiwiki.info/security/#index31h2

Original post by pooja

[2/5] ikiwiki Cross-Site Request Forgery Vulnerabilities

Related Articles:
  • [2/5] Debian update for ikiwiki
  • [2/5] OTRS Cross-Site Scripting and Cross-Site Request Forgery
  • [2/5] sBlog Cross-Site Request Forgery
  • [2/5] SkaLinks Cross-Site Request Forgery
  • [3/5] MyBB SQL Injection and Cross-Site Request Forgery Vulnerabilities


  • Posted in Advisories - Exploits | | [2/5] ikiwiki Cross-Site Request Forgery Vulnerabilities

    << [2/5] Linksys SPA2102 Phone Adapter Denial of Service | [2/5] GNU Emacs vcdiff Insecure Temporary Files >>