CVE-2014-5361

Multiple cross-site request forgery (CSRF) vulnerabilities in Landesk Management Suite 9.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) start, (2) stop, or (3) restart services via a request to remote/serverServices.aspx.
Configurations

Configuration 1 (hide)

cpe:2.3:a:landesk:landesk_management_suite:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:11

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/131496/Landesk-Management-Suite-9.5-RFI-CSRF.html - Exploit () http://packetstormsecurity.com/files/131496/Landesk-Management-Suite-9.5-RFI-CSRF.html - Exploit
References () http://www.securityfocus.com/archive/1/535286/100/0/threaded - () http://www.securityfocus.com/archive/1/535286/100/0/threaded -

Information

Published : 2015-04-21 15:59

Updated : 2024-11-21 02:11


NVD link : CVE-2014-5361

Mitre link : CVE-2014-5361

CVE.ORG link : CVE-2014-5361


JSON object : View

Products Affected

landesk

  • landesk_management_suite
CWE
CWE-352

Cross-Site Request Forgery (CSRF)