WebCalendar 1.2.7 CSRF Bypass

Discussion in 'News Aggregator' started by Packet Storm, 6 Jul 2016.

  1. Packet Storm

    Packet Storm Guest

    WebCalendar version 1.2.7 attempts to uses the HTTP Referer to check that requests are originating from same server. However, this can be easily defeated by just not sending a referer.

    Continue reading...
     

Share This Page

Loading...