MKPortal M1.1.1 (Urlobox) Cross Site Request Forgery Vulnerability
2006-12-21 00:00:00MkPortal Urlobox Cross Site Request Forgery
Discovered by: Demential
Web: http://www.burnhead.it
E-mail: [email protected]
Mkportal website: http://www.mkportal.it
posting [img]?ind=urlobox&op=delete&idurlo=X[/img] in MkPortal urlobox
where X is an ID of a message,
when administrator opens urlobox page message X will be erased.
#
Fixes
No fixesIn order to submit a new fix you need to be registered.

