The Cherokee server admin configuration web interface suffers from a cross site request forgery vulnerability.
6274758ba4e4c8e66d6a30f8efa1c215Vendor response: "This isn't an issue."
Problem: the cherokee server admin configuration web interface is
vulnerable to csrf.
Impact: if an admin is logged into the cherokee admin interface and
visits a site which runs "bad tm scripts" cherokee can be reconfigured
to run as $user and set log handlers(hooks) to execute arbitrary
commands (on error and on access).
Comments
No comments yet, be the first!