RULE(RULE ID:312266)

Rule General Information
Release Date: 2015-12-31
Rule Name: Ignite Realtime Openfire Cross-site Request Forgery Vulnerability -2 (CVE-2015-6973)
Severity:
CVE ID:
Rule Protection Details
Description: Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via a crafted request to user-password.jsp, (2) add users via a crafted request to user-create.jsp, (3) edit server settings or (4) disable SSL on the server via a crafted request to server-props.jsp, or (5) add clients via a crafted request to plugins/clientcontrol/permitted-clients.jsp.
Impact: An attacker can launch a cross-site request forgery in the context of the affected software. Arbitrary script transmitted from a user that the software trusts can be executed in a successful exploit attempt.
Affected OS: Windows, Solaris, Other Unix, FreeBSD, Linux
Reference: ExploitDB:38192
Solutions
No information about possible solutions is published. Please use an alternative product to substitude the affected software.