Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Samba SWAT 跨站请求伪造漏洞
Vulnerability Description
Samba是Samba团队开发的一套可使UNIX系列的操作系统与微软Windows操作系统的SMB/CIFS网络协议做连结的自由软件。该软件支持共享打印机、互相传输资料文件等。 Samba 3.5.21之前的3.x版本,3.6.12之前的3.6.x版本,4.0.2之前的4.x版本中的Samba Web Administration Tool (SWAT)中存在跨站请求伪造漏洞。通过使用密码和执行SWAT操作的组成请求等方法,远程攻击者利用该漏洞劫持任意用户身份验证。
CVSS Information
N/A
Vulnerability Type
N/A