Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.902066
Category:Web application abuses
Title:Brekeke PBX CSRF Vulnerability
Summary:Brekeke PBX is prone to a cross-site request forgery (CSRF) vulnerability.
Description:Summary:
Brekeke PBX is prone to a cross-site request forgery (CSRF) vulnerability.

Vulnerability Insight:
The flaw exists in the application which fails to perform
validity checks on certain 'HTTP reqests', which allows an attacker to hijack
the authentication of users for requests that change passwords via the
pbxadmin.web.PbxUserEdit bean.

Vulnerability Impact:
Successful exploitation will allow attackers to change the
administrator's password by tricking a logged in administrator into visiting a
malicious web site.

Affected Software/OS:
Brekeke PBX version 2.4.4.8.

Solution:
Upgrade to Brekeke PBX version 2.4.6.7 or later.

CVSS Score:
2.6

CVSS Vector:
AV:N/AC:H/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-2114
http://cross-site-scripting.blogspot.com/2010/05/brekeke-pbx-2448-cross-site-request.html
http://osvdb.org/64950
http://secunia.com/advisories/39952
CopyrightCopyright (C) 2010 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.