Unrated severityNVD Advisory· Published Jun 27, 2012· Updated Apr 29, 2026
CVE-2012-3231
CVE-2012-3231
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in web@all 2.0, as downloaded before May 30, 2012, allow remote attackers to hijack the authentication of administrators for requests that add, delete, or modify sensitive information, as demonstrated by adding a file to execute arbitrary code via a do_addfile action to inc/browser/action.php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/54109nvdExploit
- www.htbridge.com/advisory/HTB23094nvdExploit
News mentions
0No linked articles in our index yet.