PoC Index

CVE-2009-0039

MEDIUM 6.8EPSS 11.1%

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.

CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
11.06% chance of exploitation in the next 30 days, 96th percentile
Published
2009-04-17
Updated
2024-08-07

ExploitDB entries (1)

References

Related