CVE-2008-6729

Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that modify an account via the (1) password or (2) email_address parameter.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:phpmotion:phpmotion:2.0:*:*:*:*:*:*:*
cpe:2.3:a:phpmotion:phpmotion:1.0:*:*:*:*:*:*:*
cpe:2.3:a:phpmotion:phpmotion:*:*:*:*:*:*:*:*

Information

Published : 2009-04-20 07:30

Updated : 2017-09-28 18:33


NVD link : CVE-2008-6729

Mitre link : CVE-2008-6729


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

phpmotion

  • phpmotion