Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-0563 (Liferay Enterprise Portal)

BugsAlert Home > CVE-2008-0563 (Liferay Enterprise Portal)
 
 

Cross-site request forgery (CSRF) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to perform unspecified actions as unspecified authenticated users via the User-Agent HTTP header, which is used when composing Forgot Password e-mail messages in HTML format.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0563

Learn more about CVE-2008-0563 (Liferay Enterprise Portal)
 

Related Items

      WORM_BAGLE.SS

      CVE-2008-1066 (Smarty)

      Debian: New yarssr packages fix arbitrary shell command

      RedHat: Moderate: JBoss Enterprise Application Platform

      CVE-2007-6421 (Apache HTTP Server)

      CVE-2008-1878 (xine-lib)

      Bugtraq: ANNOUNCE: Apache-SSL security release - apache_1.3.41+ssl_1.59

 

Pixel