CVE-2008-6585: CSRF
Published Apr 3, 2009
·Updated
Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack the authentication of administrators for requests that add new accounts via the addUser action.
Affected Software
1 affected component
TorrentFlux TorrentFlux=2.3
Event History
Apr 3, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6585?
The severity of CVE-2008-6585 is considered medium due to the potential for unauthorized account creation.
2
How do I fix CVE-2008-6585?
To fix CVE-2008-6585, ensure that proper anti-CSRF tokens are implemented in requests that modify user accounts.
3
Who is affected by CVE-2008-6585?
CVE-2008-6585 affects administrators of TorrentFlux version 2.3.
4
Can CVE-2008-6585 be exploited remotely?
Yes, CVE-2008-6585 can be exploited remotely by attackers to hijack administrator sessions.
5
What action does CVE-2008-6585 allow an attacker to perform?
CVE-2008-6585 allows attackers to add new user accounts without authorization.