CVE-2007-6490: CSRF
Published Dec 20, 2007
·Updated
Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain changepass action to index.php.
Affected Software
1 affected component
Falcon Series One CMS=1.4.3
Event History
Dec 20, 2007
CVE Published
08:46 PM
Dec 21, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6490?
CVE-2007-6490 is classified as a medium severity vulnerability due to its impact on user account security.
2
How do I fix CVE-2007-6490?
To fix CVE-2007-6490, update to the latest version of Falcon Series One CMS that addresses the CSRF vulnerability.
3
What systems are affected by CVE-2007-6490?
CVE-2007-6490 affects the Falcon Series One CMS version 1.4.3.
4
What type of vulnerability is CVE-2007-6490?
CVE-2007-6490 is a Cross-site request forgery (CSRF) vulnerability.
5
What can attackers achieve with CVE-2007-6490?
Attackers can exploit CVE-2007-6490 to change user passwords without authorization.