CVE-2011-5284: CSRF
Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to hijack the authentication of administrators for requests that perform a reboot via a request to cgi-bin/shutdown.cgi.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5284?
CVE-2011-5284 has a medium severity due to its potential for remote exploitation via cross-site request forgery.
How do I fix CVE-2011-5284?
To fix CVE-2011-5284, update your Smoothwall Express to version 3.1 or later, or apply the available security patches.
Which versions are affected by CVE-2011-5284?
CVE-2011-5284 affects Smoothwall Express versions 3.0 SP3 and earlier, including 3.1.
What type of vulnerability is CVE-2011-5284?
CVE-2011-5284 is classified as a cross-site request forgery (CSRF) vulnerability.
Can CVE-2011-5284 allow unauthorized access?
Yes, CVE-2011-5284 can allow unauthorized remote attackers to hijack the authentication of administrators.