CVE-2012-3362
UnknownEPSS 0.89%
Last modified
CVE-2012-3362 is a vulnerability of currently unknown severity. Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an adduser admin action.. EPSS estimates a 0.89% chance of exploitation in the next 30 days.
Description
Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an adduser admin action.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Extplorer | Extplorer | <= 2.1.0 | Rc3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-3362?
Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an adduser admin action.
How severe is CVE-2012-3362?
Severity scoring for CVE-2012-3362 is pending analysis. The EPSS model estimates a 0.89% probability of exploitation in the next 30 days.
How do I fix CVE-2012-3362?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-3356The remote SVN views functionality (lib/vclib/svn/svn_ra.py)…
- CVE-2012-3357The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC…
- CVE-2012-3358Multiple heap-based buffer overflows in the j2k_read_sot fun…
- CVE-2012-3359Luci in Red Hat Conga stores the user's username and passwor…
- CVE-2012-3360Directory traversal vulnerability in virt/disk/api.py in Ope…
- CVE-2012-3361virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2)…
- CVE-2012-3363Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x …9.1
- CVE-2012-3364Multiple stack-based buffer overflows in the Near Field Comm…
- CVE-2012-3365The SQLite functionality in PHP before 5.3.15 allows remote …
- CVE-2012-3366The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote…
- CVE-2012-3367Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Ce…
- CVE-2012-3368Integer signedness error in attach.c in dtach 0.8 allows rem…
Are you affected by CVE-2012-3362?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
