CVE-2008-6478: CSRF
Cross-site request forgery (CSRF) vulnerability in the file manager in the VZPP web interface for Parallels Virtuozzo 365.6.swsoft (build 4.0.0-365.6.swsoft) and 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote attackers to create and delete arbitrary files as the administrator via a link or IMG tag to (1) create-file and (2) list-control in vz/cp/vzdir/infrman/envs/files/; or modify system configuration via the path parameter to vz/cp/vzdir/infrman/envs/files/index.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the VZPP web interface (the Parallels Virtuozzo VZPP management UI) to trusted/management IP addresses via firewall, network ACLs, or a web application firewall. Specifically block or limit external access to endpoints under /vz/cp/vzdir/infrman/envs/files/ (including create-file, list-control, and the index path that accepts the path parameter) so only trusted networks or administrators can reach them.
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6478?
CVE-2008-6478 is classified as a high severity vulnerability due to its potential to allow remote attackers to manipulate files arbitrarily as an administrator.
How do I fix CVE-2008-6478?
To fix CVE-2008-6478, it is recommended to upgrade to the latest version of Parallels Virtuozzo Containers that addresses this vulnerability.
What systems are affected by CVE-2008-6478?
CVE-2008-6478 affects Parallels Virtuozzo Containers versions 3.0.0-25.4.swsoft and 4.0.0-365.6.swsoft.
What type of vulnerability is CVE-2008-6478?
CVE-2008-6478 is a Cross-site request forgery (CSRF) vulnerability that allows unauthorized file operations.
Can CVE-2008-6478 be exploited remotely?
Yes, CVE-2008-6478 can be exploited remotely by attackers to create and delete files as an administrator.