Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
JBoss jmx-console CSRF Feb 22 2007 11:04AM
buben razuma gmail com
Hello!
Recent message about JBoss's console made me looking at that interface again and it seems that it is vulnerable for the CRSF attacks.

MBean settings may be changed and operations may be invoked on behalf of the authenticated administrator by the hidden submitting form like follows:

<form me...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus