CVE-2007-3786

** DISPUTED **

Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable software, stating that it was a custom build for a former customer.

Date published : 2007-07-15

http://www.securityfocus.com/archive/1/473663/100/0/threaded

http://labs.calyptix.com/CX-2007-05.php