Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown the server, (2) send ping packets, (3) enable network services, (4) configure a proxy server, and (5) modify other settings via parameters in the query string.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Armorlogic Profense 'ajax.html'多个跨站请求伪造和跨站脚本攻击漏洞
Vulnerability Description
Profense Web应用程序防火墙2.6.2和2.6.3版本中的ajax.html存在多个跨站请求伪造漏洞。远程攻击者可以借助query字符串中的参数,劫持对管理员请求的认证。该请求可以(1)关闭服务器,(2)发送ping信息包,(3)激活网络服务,(4)配置一个代理服务器和(5)修改其他设置。
CVSS Information
N/A
Vulnerability Type
N/A