Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Openkm MEDIUM 6.8
CVE-2012-2316

Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote att…

No fix yet
Fix from $1,600 2012-09-09
Mediawiki MEDIUM 6.8
CVE-2012-1580

Cross-site request forgery (CSRF) vulnerability in Special:Upload in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers …

Mitigation only
Fix from $1,600 2012-09-09
Mediawiki MEDIUM 6.8
CVE-2012-1578

Multiple cross-site request forgery (CSRF) vulnerabilities in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allow remote attackers to hijac…

Mitigation only
Fix from $1,600 2012-09-09
Business Availability Center MEDIUM 6.8
CVE-2012-3256

Cross-site request forgery (CSRF) vulnerability in HP Business Availability Center (BAC) 8.07 allows remote attackers to hijack the authentication of…

Mitigation only
Fix from $1,600 2012-09-08
Flatnux MEDIUM 6.8
CVE-2012-4877

Cross-site request forgery (CSRF) vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 and earlier allows remote attackers to hijack the au…

Fix: after 2011-08-09-2
Fix from $1,600 2012-09-06
Wishlist MEDIUM 6.8
CVE-2012-2069

Cross-site request forgery (CSRF) vulnerability in the Wishlist module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.6 for Drupal allows remote att…

Patch available
Fix from $1,600 2012-09-06
Owncloud MEDIUM 6.8
CVE-2012-4753

Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.5 allow remote attackers to hijack the authentication of unspecifie…

Fix: after 4.0.4
Fix from $1,600 2012-09-05
Struts MEDIUM 6.8
CVE-2012-4386

The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote…

Mitigation only
Fix from $1,600 2012-09-05
Owncloud MEDIUM 6.8
CVE-2012-4391

Cross-site request forgery (CSRF) vulnerability in core/ajax/appconfig.php in ownCloud before 4.0.7 allows remote attackers to hijack the authenticat…

Fix: after 4.0.6
Fix from $1,600 2012-09-05
Owncloud MEDIUM 6.8
CVE-2012-4393

Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.6 allow remote attackers to hijack the authentication of arbitrary …

Fix: after 4.0.5
Fix from $1,600 2012-09-05
Wikkawiki MEDIUM 6.8
CVE-2011-4452

Cross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to hijack the authen…

Patch available
Fix from $1,600 2012-09-05
Zxdsl MEDIUM 6.8
CVE-2012-4746

Cross-site request forgery (CSRF) vulnerability in accessaccount.cgi in ZTE ZXDSL 831IIV7.5.0a_Z29_OV allows remote attackers to hijack the authentic…

No fix yet
Fix from $1,600 2012-08-31
E107 MEDIUM 6.8
CVE-2011-4947

Cross-site request forgery (CSRF) vulnerability in e107_admin/users_extended.php in e107 before 0.7.26 allows remote attackers to hijack the authenti…

Fix: after 0.7.24
Fix from $1,600 2012-08-31
Commerce Reorder MEDIUM 6.8
CVE-2012-2116

Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote attackers to hijack the authen…

Fix: after 7.x-1.0
Fix from $1,600 2012-08-31
Mybb MEDIUM 6.8
CVE-2011-5131

Cross-site request forgery (CSRF) vulnerability in global.php in MyBB before 1.6.5 allows remote attackers to hijack the authentication of a user for…

Fix: after 1.6.4
Fix from $1,600 2012-08-30
Infosphere Guardium MEDIUM 6.8
CVE-2012-3309

Cross-site request forgery (CSRF) vulnerability in the account-creation panel in IBM InfoSphere Guardium 8.2 and earlier, when the CSRF filtering (ak…

Fix: after 8.2
Fix from $1,600 2012-08-29
Messaging Gateway MEDIUM 6.8
CVE-2012-0308

Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to hijack the authentication …

Fix: after 9.5.4
Fix from $1,600 2012-08-29
Dokuwiki MEDIUM 6.8
CVE-2012-2128

Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to hijack the authentication of admi…

Mitigation only
Fix from $1,600 2012-08-27
Wlm 2501 MEDIUM 6.8
CVE-2012-1921

Cross-site request forgery (CSRF) vulnerability in goform/admin/formWlEncrypt in Sitecom WLM-2501 allows remote attackers to hijack the authenticatio…

Mitigation only
Fix from $1,600 2012-08-26
Avos HIGH 9.3
CVE-2010-5191

Multiple cross-site request forgery (CSRF) vulnerabilities on the Blue Coat ProxyAV appliance before 3.2.6.1 allow remote attackers to hijack the aut…

Fix: after 3.2.6
Fix from $1,950 2012-08-26
Silverstripe MEDIUM 6.8
CVE-2010-5080

The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a …

Mitigation only
Fix from $1,600 2012-08-26
Silverstripe MEDIUM 6.8
CVE-2010-5088

Multiple cross-site request forgery (CSRF) vulnerabilities in SilverStripe 2.3.x before 2.3.9 and 2.4.x before 2.4.3 allow remote attackers to hijack…

Patch available
Fix from $1,600 2012-08-26
Websphere Mq MEDIUM 6.8
CVE-2012-3294

Multiple cross-site request forgery (CSRF) vulnerabilities in the Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier, …

Fix: after 7.0.4
Fix from $1,600 2012-08-17
Sharethis MEDIUM 5.1
CVE-2012-2077

Cross-site request forgery (CSRF) vulnerability in the ShareThis module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to hijack the authe…

Patch available
Fix from $1,600 2012-08-14
Node Limitnumber MEDIUM 6.8
CVE-2012-2080

Cross-site request forgery (CSRF) vulnerability in the Node Limit Number module before 6.x-1.2 for Drupal allows remote attackers to hijack the authe…

Fix: after 6.x-1.1
Fix from $1,600 2012-08-14
Cdn2 Video MEDIUM 6.8
CVE-2012-2155

Cross-site request forgery (CSRF) vulnerability in the CDN2 Video module 6.x for Drupal allows remote attackers to hijack the authentication of unspe…

Patch available
Fix from $1,600 2012-08-14
Autosave MEDIUM 6.8
CVE-2012-2097

Cross-site request forgery (CSRF) vulnerability in the Autosave module 6.x before 6.x-2.10 and 7.x-2.x before 7.x-2.0 for Drupal allows remote attack…

Fix: after 6.x-2.9
Fix from $1,600 2012-08-14
Vacation Rental Script MEDIUM 6.8
CVE-2012-4324

Cross-site request forgery (CSRF) vulnerability in PHPJabbers Vacation Rental Script allows remote attackers to hijack the authentication of administ…

No fix yet
Fix from $1,600 2012-08-14
News Pro MEDIUM 6.8
CVE-2012-4325

Cross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and earlier allows remote attackers to hijack the …

Fix: after 1.4.0
Fix from $1,600 2012-08-14
Site Uptime Enterprise MEDIUM 6.8
CVE-2012-4326

Cross-site request forgery (CSRF) vulnerability in commonsettings.php in AlstraSoft Site Uptime Enterprise, possibly 5.4, allows remote attackers to …

Mitigation only
Fix from $1,600 2012-08-14