Multiple cross-site request forgery (CSRF) vulnerabilities in Janetter before 3.3.0.0 (aka 3.3.0) allow remote attackers to hijack the authentication of arbitrary users for requests that (1) tweet, (2) upload an image file, or (3) execute arbitrary commands.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:36
Type | Values Removed | Values Added |
---|---|---|
References | () http://blog.janetter.net/ - | |
References | () http://janetter.net/history.html - | |
References | () http://jvn.jp/en/jp/JVN83459967/index.html - | |
References | () http://jvndb.jvn.jp/jvndb/JVNDB-2012-000027 - | |
References | () http://secunia.com/advisories/48480 - |
Information
Published : 2012-03-19 21:55
Updated : 2025-04-11 00:51
NVD link : CVE-2012-1236
Mitre link : CVE-2012-1236
CVE.ORG link : CVE-2012-1236
JSON object : View
Products Affected
janetter
- janetter
CWE
CWE-352
Cross-Site Request Forgery (CSRF)