CVE-2007-3786

Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable software, stating that it was a custom build for a former customer
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:esoft:instagate_ex2_utm:firmware_3.1.20031001:*:*:*:*:*:*:*
cpe:2.3:h:esoft:instagate_ex2_utm:firmware_3.1.20060921:*:*:*:*:*:*:*
cpe:2.3:h:esoft:instagate_ex2_utm:firmware_3.1.20070605:*:*:*:*:*:*:*

History

07 Nov 2023, 02:00

Type Values Removed Values Added
References
  • {'url': 'http://www.eweek.com/article2/0,1759,2154646,00.asp', 'name': 'http://www.eweek.com/article2/0,1759,2154646,00.asp', 'tags': [], 'refsource': 'MISC'}
  • () http://www.eweek.com/article2/0%2C1759%2C2154646%2C00.aspĀ -
Summary ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable software, stating that it was a custom build for a former customer. Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable software, stating that it was a custom build for a former customer

Information

Published : 2007-07-15 23:30

Updated : 2024-04-11 00:42


NVD link : CVE-2007-3786

Mitre link : CVE-2007-3786

CVE.ORG link : CVE-2007-3786


JSON object : View

Products Affected

esoft

  • instagate_ex2_utm