Cosign CVE-2007-2233 Cross-Site Request Forgery Vulnerability

Cosign is prone to a cross-site request forgery vulnerability. cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.


 

Privacy Statement
Copyright 2010, SecurityFocus