CVE-2014-10001
PHPJabbers Appointment Scheduler 2.0 - Multiple Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices controller or (2) add an administrator via a pjActionCreate action to the pjAdminUsers controller.
Múltiples vulnerabilidades de CSRF en PHPJabbers Appointment Scheduler 2.0 permiten a atacantes remotos secuestrar la autenticación de administradores para solicitudes que (1) realizan ataques de XSS a través del parámetro i18n[1][name] en una acción pjActionCreate en el controlador pjAdminServices o (2) añaden un administrador a través de una acción pjActionCreate en el controlador pjAdminUsers.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-01-14 First Exploit
- 2015-01-13 CVE Reserved
- 2015-01-13 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/56377 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/90419 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/90420 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/30911 | 2014-01-14 | |
http://packetstormsecurity.com/files/124755 | 2024-08-06 | |
http://www.exploit-db.com/exploits/30911 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Phpjabbers Search vendor "Phpjabbers" | Appointment Scheduler Search vendor "Phpjabbers" for product "Appointment Scheduler" | 2.0 Search vendor "Phpjabbers" for product "Appointment Scheduler" and version "2.0" | - |
Affected
|