HP System Management Homepage CVE-2011-3846 Cross Site Request Forgery Vulnerability

HP System Management Homepage is prone to a cross-site request-forgery vulnerability.



Exploiting this issue may allow a remote attacker to perform certain administrative actions such as creating an arbitrary user with administrative privileges. Other attacks are also possible.



HP System Management Homepage 6.2.2.7 is vulnerable; other versions may also be affected.


 

Privacy Statement
Copyright 2010, SecurityFocus