Vulnerabilities > CVE-2014-6607 - Credentials Management vulnerability in Mmonit M/Monit

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
mmonit
CWE-255
exploit available

Summary

M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via the fullname and password parameters, a different vulnerability than CVE-2014-6409.

Vulnerable Configurations

Part Description Count
Application
Mmonit
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionM/Monit 3.3.2 - CSRF Vulnerability. CVE-2014-6409. Webapps exploit for php platform
fileexploits/php/webapps/34718.txt
idEDB-ID:34718
last seen2016-02-03
modified2014-09-20
platformphp
port
published2014-09-20
reporterDolev Farhi
sourcehttps://www.exploit-db.com/download/34718/
titleM/Monit 3.3.2 - CSRF Vulnerability
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/128321/mmonit-xsrf.txt
idPACKETSTORM:128321
last seen2016-12-05
published2014-09-19
reporterDolev Farhi
sourcehttps://packetstormsecurity.com/files/128321/M-Monit-3.2.2-Cross-Site-Request-Forgery.html
titleM/Monit 3.2.2 Cross Site Request Forgery