CVE-2012-2999
Published Oct 4, 2012
Last updated 12 years ago
Overview
- Description
- Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in Cerberus FTP Server before 5.0.5.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user account or (2) reconfigure the state of the FTP service, as demonstrated by a request to usermanager/users/modify.
- Source
- cret@cert.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-352
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F54BD273-3356-4EB7-A5D1-1018E5A4D58C", "versionEndIncluding": "5.0.4.3" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:1.0:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B584BB0D-C9F0-42E4-8CB2-F7AFB31884A6" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:1.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E35C53A7-91D6-46F3-B294-07FCB721AF05" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "664176FA-1775-46AF-9EA2-3B5C96A36A05" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D6D98E88-557E-4249-8D30-4F1EE7ECE5C5" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:1.02:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7097C6AD-6BE7-4267-9C88-E097A0CFC0EC" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:1.03:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80EB8701-85F8-4BA5-8A93-1B47E655B8B9" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "207A3423-BE63-4B3A-BC28-8643048C096F" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:1.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91BB1247-BE77-4075-B6AE-5E28A3D9B594" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:1.6:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D69CDFCD-ACA9-42E9-BBD8-90F6A69E4468" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9590014E-7F1A-4799-80FE-9041192D3CBB" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:1.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "67B56FFF-E508-476D-B2AD-24DC999F3582" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:1.71:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA0854BD-2D96-403C-BB22-BC1BE162E241" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B36CD14-4E0E-4238-9AEA-37D879F995A2" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3B0F42BB-61DB-4268-9092-05052D478AB2" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "819A6EF5-107C-47DF-BFFD-5BA29428F280" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.0:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "117D42CD-F063-41CD-AABF-A0C96E35D838" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.0:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "62D032F0-28E2-4EB2-A3DC-67413BF08C4D" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5EEDD9AC-75E7-49F3-9362-D4B99A944C3A" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B1DCA79-73FA-46D4-AF57-074373DE7503" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.02:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80D47E85-BB68-4C4D-8888-25422AC4B76D" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E842263-7AF3-463D-814D-F63199F3C21B" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.02:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C63CED4F-F823-4310-AD78-11B5C82167E2" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.2:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3445BC51-DB9F-4E14-B0DE-806FBCD9641E" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.2:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7454163-9481-4CBD-85CB-9C6798181E05" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.2:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3F169EEB-89E1-4248-A185-38433D1A8573" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD5D97C7-5A06-44EF-BF46-F5DE3C30F16E" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DC1FA9C0-77D0-403C-ADED-7D9E89BFFC96" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.4:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C4B7B5AB-3C5E-4D9A-816C-892FD4DA3284" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.4:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EBF4BA1E-5B31-42FD-897A-455FDF9C0A15" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.4:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FCE4860E-8A9F-4E38-81DC-291F317E8700" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35F0613F-FD01-4E57-BD8F-181DC14A948C" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.11:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "620FAAEE-A52D-4710-BCB0-3D07F1453BF8" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.11:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FBE8B552-FA88-4C5C-9296-6BC9908E3F2C" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B752D925-6A84-4885-A697-D868C06B1E25" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.15:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "29440529-9BDA-4738-853E-85E54CB951C3" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C3E6A73-0475-46AB-9B88-690A39D3E411" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.21:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CF2C736-C686-4501-A4AE-227ABC218EBF" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F59FE48-F91C-45FD-BB3C-4F5186C430D5" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.23:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EEA0F5DF-228C-4F01-8A8F-90A9A6FBDF10" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.31:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D0D9A2E-6B38-437F-B89C-AC7546057B6A" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.32:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2093E888-B80F-4318-AD14-CE0295E3B0E7" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.41:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E6B0C7F7-9349-4AC9-8D74-E2C8AB1F0C13" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.42:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23B56CAD-6783-46E5-A82D-EB2A14A8A354" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.43:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "14182912-05FE-4CD3-B457-6EFF91D8DF42" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.44:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B06481D-2BB9-4A56-AE8B-1A264B4EE207" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.45:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FB03F569-A146-4D9D-B065-46D95BE8FDF8" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.46:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "543E96D3-6882-405C-9E9C-0B36D426C0F7" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.47:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C87C96DD-5302-45CB-B95D-3D174420CE99" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.48:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8F27A27-2596-4562-B739-083EBF272763" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.49:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "01A7296B-F5F4-43E2-8527-304EEA996629" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:2.50:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1ABED3D7-4B80-46D8-88F4-0F66510D2E2B" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6BC21599-EB4C-49CD-A046-13148102E43F" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "363BB778-0C5C-4FEC-BC82-250C026BDE06" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0761D7FE-1EB2-4D94-BD38-2F7B8AA8970B" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "883FE03E-555B-49E7-BECA-8554F05D007E" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E9C71CB9-59D4-44BC-BD79-2E3004D3A1C3" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5512BB61-B912-407F-8398-E49D05B2887C" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BDC63773-FBA3-45CF-95DC-AE86D621217E" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9EF37E3B-B1E3-4200-9A5B-34FCBFAC830A" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.0.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4BF3E234-FB2A-4906-A3E2-E08A8BCDB1BF" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "074DDB0D-D55A-4BB5-AF54-82AE2453AB0F" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7816C89-2D67-463E-B2B7-B4ACEB24F89B" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9CC79111-1B16-4C8D-BEF3-578789D7F662" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.1.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D846F22D-3BED-4D12-8B0D-99AF20FF1FA8" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.1.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0EC052F4-074D-4A1C-ACF9-628782345430" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0923BF4-AC10-4DC0-BF1B-6AE80D5C51B4" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CE2E29B7-BB38-430B-949A-EDCA45833CCE" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1AE9FE3C-8ED8-4CDA-B032-42BEB08C446D" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39D76CD3-EBAB-4847-A570-D2C0C5B0DC7F" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:3.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "837B942E-8815-4C27-ABF1-4B3131C3CFD8" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:4.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3F3EBCA3-E786-49CB-8CAF-34D35D4A3C83" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:4.0.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FB613A86-7837-4C5B-9194-3238D9BD2F45" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:4.0.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "018B6603-904D-42FA-B1C3-6EAD3CE6B8E3" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:4.0.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2738E91-6B27-4918-8CFD-FB17685D431A" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:4.0.0.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BA7BCD1A-8EC9-4527-AA66-A3C109D6064C" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:4.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A46EFDE2-8E57-4102-8DC0-F8D626D5C052" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:4.0.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "281FCCA7-0558-4230-A295-43D8588103A7" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:4.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EB7F85EE-3412-467E-A3B5-D9828CBCE31C" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:4.0.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FBE639D4-7B95-4E0A-8E34-A33D25F7EFB9" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E2E1E01-7F35-4ABA-9105-ECBB68899485" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "53024BD3-68C8-4C0B-BC6A-47B495094FFC" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D5022CA1-F5D4-430F-AFEA-52575FDCD7E1" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "14FC2D7A-34EB-4C56-BE7E-B131DBA817B5" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B911C27F-79B8-4362-99F1-A54A50CB2BF7" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F1EFBAB9-CE22-41A2-8F31-322DD10B06E6" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B4BDBF7-337C-4CC0-8C9B-062CA6B1C254" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3AECC625-FB34-468D-8FE9-B47C06F964F0" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7BEF8406-AABD-4662-A120-DB62B4777FCD" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F391EB76-A9CC-4E3F-8174-980FCB715847" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C05E2DDE-FD5A-4BDB-BDE4-8E2B0C26F77F" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A695B11F-7EA3-4F25-9235-806132131EF1" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "765B829B-78E8-4D5D-B0BF-70E6E6896FF4" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "588137BE-E566-4265-8AF8-BB0AF4F3AC88" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8CD056AD-E033-457E-879C-59E113347606" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3185B882-BA96-47F2-BFB3-15F54B87B30D" }, { "criteria": "cpe:2.3:a:cerberusftp:ftp_server:5.0.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3394D029-0A78-4F60-BEBE-B00F52145B95" } ], "operator": "OR" } ] } ]