Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-4311
Description:Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-4311
BugTraq ID: 92485
http://www.securityfocus.com/bid/92485
Bugtraq: 20160813 WSO2 IDENTITY-SERVER v5.1.0 XML External-Entity (Google Search)
http://www.securityfocus.com/archive/1/539199/100/0/threaded
https://www.exploit-db.com/exploits/40239/
http://hyp3rlinx.altervista.org/advisories/WSO2-IDENTITY-SERVER-v5.1.0-XML-External-Entity.txt
http://packetstormsecurity.com/files/138329/WSO2-Identity-Server-5.1.0-XML-Injection.html




© 1998-2025 E-Soft Inc. All rights reserved.