>> Hyper Estraier "communicate()" Function Cross Site Request Forgery Vulnerability
Title : Hyper Estraier "communicate()" Function Cross Site Request Forgery Vulnerability VUPEN ID : VUPEN/ADV-2006-2827 CVE ID : CVE-2006-3671
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-07-17
Technical Description
A vulnerability has been identified in Hyper Estraier, which could be exploited by attackers to manipulate certain information. This flaw is due to an error in the "communicate()" [estmaster.c] function that does not validate certain HTTP requests, which could be exploited by malicious people to conduct cross site request forgery attacks.