First published: Tue Apr 07 2009(Updated: )
Cross-site request forgery (CSRF) vulnerability in admin.php in AjaXplorer 2.3.3 and 2.3.4 allows remote attackers to hijack the authentication of administrators for requests that modify passwords via the update_user_pwd action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ajaxplorer | =2.3.3 | |
Ajaxplorer | =2.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6639 is classified as a high severity vulnerability due to the risk of cross-site request forgery allowing attackers to hijack administrator sessions.
To fix CVE-2008-6639, upgrade AjaXplorer to a version later than 2.3.4 where this vulnerability is addressed.
CVE-2008-6639 can be exploited to modify user passwords by hijacking the authentication of administrators.
CVE-2008-6639 affects AjaXplorer versions 2.3.3 and 2.3.4.
Administrators using AjaXplorer versions 2.3.3 and 2.3.4 are vulnerable to attacks exploiting CVE-2008-6639.