CVE-2011-0503
Last modified
CVE-2011-0503 is a vulnerability of currently unknown severity. Cross-site request forgery (CSRF) vulnerability in VaM Shop 1.6, 1.6.1, and probably earlier versions allows remote attackers to hijack the authentication of administrators for requests that (1) change user status via admin/customers.php or (2) change user permissions via admin/accounting.php. NOTE: some of these details are obtained from third party information.. EPSS estimates a 2.11% chance of exploitation in the next 30 days.
Description
Cross-site request forgery (CSRF) vulnerability in VaM Shop 1.6, 1.6.1, and probably earlier versions allows remote attackers to hijack the authentication of administrators for requests that (1) change user status via admin/customers.php or (2) change user permissions via admin/accounting.php. NOTE: some of these details are obtained from third party information.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vamsoft | Vam Shop | <= 1.6.1 |
| Vamsoft | Vam Shop | 1.6 |
References
- http://secunia.com/advisories/42869Vendor Advisory
- http://secunia.com/advisories/42869Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-0503?
How severe is CVE-2011-0503?
How do I fix CVE-2011-0503?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-0497Directory traversal vulnerability in Sybase EAServer 6.x bef…
- CVE-2011-0498Stack-based buffer overflow in Nokia Multimedia Player 1.00.…
- CVE-2011-0499Buffer overflow in VideoSpirit Pro 1.6.8.1 and possibly earl…
- CVE-2011-0500Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlie…
- CVE-2011-0501Stack-based buffer overflow in Music Animation Machine MIDI …
- CVE-2011-0502Music Animation Machine MIDI Player 2006aug19 Release 035 an…
- CVE-2011-0504Multiple cross-site scripting (XSS) vulnerabilities in VaM S…
- CVE-2011-0505Directory traversal vulnerability in system/system.php in Zw…
- CVE-2011-0506Directory traversal vulnerability in modules/profile/user.ph…
- CVE-2011-0507FTPService.exe in Blackmoon FTP 3.1 Build 1735 and Build 173…
- CVE-2011-0508Cross-site scripting (XSS) vulnerability in system/modules/c…
- CVE-2011-0509Cross-site scripting (XSS) vulnerability in Vaadin before 6.…
Are you affected by CVE-2011-0503?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
