Total
4240 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-15851 | 1 Flexocms Project | 1 Flexo Cms | 2018-10-17 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in Flexo CMS v0.1.6. There is a CSRF vulnerability that can add an administrator via /admin/user/add. | |||||
CVE-2018-15848 | 1 Portfoliocms Project | 1 Portfoliocms | 2018-10-17 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in portfolioCMS 1.0.5. There is CSRF to create new pages via admin/portfolio.php?newpage=true. | |||||
CVE-2018-15850 | 1 Redaxo | 1 Redaxo Cms | 2018-10-17 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.php?page=user. | |||||
CVE-2018-15849 | 1 Portfoliocms Project | 1 Portfoliocms | 2018-10-17 | 4.3 MEDIUM | 4.3 MEDIUM |
An issue was discovered in portfolioCMS 1.0.5. There is CSRF to update the website settings via admin/aboutus.php. | |||||
CVE-2018-15844 | 1 Damicms | 1 Damicms | 2018-10-17 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit. | |||||
CVE-2018-15846 | 1 Fledrcms Project | 1 Fledrcms | 2018-10-17 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in fledrCMS through 2014-02-03. There is a CSRF vulnerability that can change the administrator's password via index.php?p=done&savedata=1. | |||||
CVE-2018-15845 | 1 Gleezcms | 1 Gleez Cms | 2018-10-17 | 6.8 MEDIUM | 8.8 HIGH |
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add. | |||||
CVE-2015-7446 | 1 Ibm | 5 Flashsystem 9846-ac2, Flashsystem 9846-ae2, Flashsystem 9848-ac2 and 2 more | 2018-10-17 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in IBM Flash System V9000 7.4 before 7.4.1.4, 7.5 before 7.5.1.3, and 7.6 before 7.6.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |||||
CVE-2007-1520 | 1 Phpnuke | 1 Php-nuke | 2018-10-16 | 6.8 MEDIUM | N/A |
The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows remote attackers to conduct CSRF attacks. | |||||
CVE-2007-1157 | 1 Jboss | 1 Jboss | 2018-10-16 | 7.6 HIGH | N/A |
Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administrators via certain MBean operations, a different vulnerability than CVE-2006-3733. | |||||
CVE-2007-0044 | 1 Adobe | 3 Acrobat, Acrobat 3d, Acrobat Reader | 2018-10-16 | 4.3 MEDIUM | N/A |
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding." | |||||
CVE-2008-0575 | 1 Webspell | 1 Webspell | 2018-10-15 | 4.3 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmin privilege level to arbitrary accounts as administrators via an "update member" action. | |||||
CVE-2008-0508 | 1 Wordpress | 1 Permalinks Migration Plugin | 2018-10-15 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows remote attackers to modify the oldstructure (aka dean_pm_config[oldstructure]) configuration setting as administrators via the old_struct parameter in a deans_permalinks_migration.php action to wp-admin/options-general.php, as demonstrated by placing an XSS sequence in this setting. | |||||
CVE-2008-0472 | 1 Woltlab | 1 Burning Board | 2018-10-15 | 4.3 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via a thread_del action. | |||||
CVE-2008-0471 | 1 Phpbb | 1 Phpbb | 2018-10-15 | 4.3 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action. | |||||
CVE-2008-0228 | 1 Linksys | 1 Wrt54gl | 2018-10-15 | 9.3 HIGH | N/A |
Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote attackers to perform actions as administrators. | |||||
CVE-2008-0198 | 1 Wordpress | 1 Wordpress | 2018-10-15 | 4.3 MEDIUM | N/A |
Multiple cross-site request forgery (CSRF) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) wpcf_question, (2) wpcf_success_msg, or (3) wpcf_error_msg parameter to wp-admin/admin.php. | |||||
CVE-2008-0164 | 1 Plone | 1 Plone Cms | 2018-10-15 | 4.3 MEDIUM | N/A |
Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote attackers to (1) add arbitrary accounts via the join_form page and (2) change the privileges of arbitrary groups via the prefs_groups_overview page. | |||||
CVE-2008-0266 | 1 Eticket | 1 Eticket | 2018-10-15 | 2.6 LOW | N/A |
Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administrative tasks. NOTE: either the old password must be known, or the attacker must leverage a separate SQL injection vulnerability. | |||||
CVE-2007-6708 | 1 Linksys | 1 Wag54gs | 2018-10-15 | 4.3 MEDIUM | N/A |
Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware allow remote attackers to perform actions as administrators via an arbitrary valid request to an administrative URI, as demonstrated by (1) a Restore Factory Defaults action using the mtenRestore parameter to setup.cgi and (2) creation of a user account using the sysname parameter to setup.cgi. |