Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."
Published at: December 29, 2017 at 10:29PM
View on website
New vulnerability on the NVD: CVE-2014-0120
Tag: government hack NVD security
No comments: