The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows remote attackers to conduct CSRF attacks.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2007-03-20 13:19
Updated : 2018-10-16 09:38
NVD link : CVE-2007-1520
Mitre link : CVE-2007-1520
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
phpnuke
- php-nuke