Required CVE Record Information
Description
Cross-site request forgery (CSRF) vulnerability in Microdasys before 3.5.1-B708, as used in Bloxx Web Filtering before 5.0.14 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that trigger error pages containing XSS sequences, a different vulnerability than CVE-2012-2564.
References 2 Total
- http://www.kb.cert.org/vuls/id/MAPG-8R9LBY
- kb.cert.org: VU#722963 third-party-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- http://www.kb.cert.org/vuls/id/MAPG-8R9LBY x_transferred
- kb.cert.org: VU#722963 third-party-advisoryx_transferred