Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Secure Access Control Server MEDIUM 6.8
CVE-2011-3293

Multiple cross-site request forgery (CSRF) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attack…

Mitigation only
Fix from $1,600 2012-05-02
Owncloud MEDIUM 6.8
CVE-2012-2397

Cross-site request forgery (CSRF) vulnerability in ownCloud before 3.0.3 allows remote attackers to hijack the authentication of arbitrary users for …

Fix: after 3.0.2
Fix from $1,600 2012-04-20
Helix Server MEDIUM 6.8
CVE-2012-1985

Cross-site request forgery (CSRF) vulnerability in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to hi…

Mitigation only
Fix from $1,600 2012-04-17
System Management Homepage MEDIUM 6.8
CVE-2011-3846

Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 6.2.2.7 allows remote attackers to hijack the authentication o…

Mitigation only
Fix from $1,600 2012-04-12
Sencha Sns MEDIUM 6.8
CVE-2012-1237

Cross-site request forgery (CSRF) vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack the authentication of arbitrary users.

Fix: after 1.0.1
Fix from $1,600 2012-04-06
Drupal MEDIUM 6.8
CVE-2007-6752

Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users fo…

Fix: after 7.12
Fix from $1,600 2012-03-28
Scalar I500 Firmware MEDIUM 6.0
CVE-2012-1843

Cross-site request forgery (CSRF) vulnerability in saveRestore.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100)…

Mitigation only
Fix from $1,600 2012-03-22
Janetter MEDIUM 6.8
CVE-2012-1236

Multiple cross-site request forgery (CSRF) vulnerabilities in Janetter before 3.3.0.0 (aka 3.3.0) allow remote attackers to hijack the authentication…

Fix: after 3.2.1.1
Fix from $1,600 2012-03-19
Webfoliocms1.0.2 MEDIUM 6.8
CVE-2012-1498

Multiple cross-site request forgery (CSRF) vulnerabilities in Webfolio CMS 1.1.4 and earlier allow remote attackers to hijack the authentication of a…

No fix yet
Fix from $1,600 2012-03-19
Contao Cms MEDIUM 6.8
CVE-2012-1297

Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hi…

Fix: after 2.11.0
Fix from $1,600 2012-03-19
Vshield Manager MEDIUM 6.8
CVE-2012-1514

Cross-site request forgery (CSRF) vulnerability in VMware vShield Manager (vSM) 1.0.1 before Update 2 and 4.1.0 before Update 2 allows remote attacke…

Fix: after 4.1
Fix from $1,600 2012-03-16
Maximo Asset Management MEDIUM 6.8
CVE-2011-1397

Cross-site request forgery (CSRF) vulnerability in the Labor Reporting page in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, …

Mitigation only
Fix from $1,600 2012-03-13
Movable Type MEDIUM 6.8
CVE-2012-0317

Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers…

Fix: after 4.37
Fix from $1,600 2012-03-03
Bugzilla MEDIUM 5.1
CVE-2012-0453

Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows…

Patch available
Fix from $1,600 2012-02-25
11in1 MEDIUM 6.8
CVE-2012-0997

Cross-site request forgery (CSRF) vulnerability in admin/index.php in 11in1 1.2.1 stable 12-31-2011 allows remote attackers to hijack the authenticat…

No fix yet
Fix from $1,600 2012-02-24
Advantech Webaccess MEDIUM 6.0
CVE-2012-0235

Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of un…

Fix: after 6.0
Fix from $1,600 2012-02-21
Advantech Webaccess MEDIUM 6.0
CVE-2012-1235

Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of…

Fix: after 6.0
Fix from $1,600 2012-02-21
Gazie MEDIUM 6.8
CVE-2012-1220

Cross-site request forgery (CSRF) vulnerability in modules/config/admin_utente.php in GAzie 5.20 and earlier allows remote attackers to hijack the au…

Fix: after 5.20
Fix from $1,600 2012-02-21
Pluck MEDIUM 6.8
CVE-2012-1227

Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in pluck 4.7 allow remote attackers to hijack the authentication of admins fo…

No fix yet
Fix from $1,600 2012-02-21
Pbboard MEDIUM 6.8
CVE-2012-1216

Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in PBBoard 2.1.4 allow remote attackers to hijack the authentication of admin…

No fix yet
Fix from $1,600 2012-02-21
Amethyst MEDIUM 6.8
CVE-2010-5085

Multiple cross-site request forgery (CSRF) vulnerabilities in admin/update_user in Hulihan Amethyst 0.1.5, and possibly earlier, allow remote attacke…

No fix yet
Fix from $1,600 2012-02-14
E107 MEDIUM 6.0
CVE-2010-5084

The cross-site request forgery (CSRF) protection mechanism in e107 before 0.7.23 uses a predictable random token based on the creation date of the ad…

Fix: after 0.7.22
Fix from $1,600 2012-02-14
Terminal MEDIUM 6.8
CVE-2012-1083

Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to…

Fix: after 0.3.2
Fix from $1,600 2012-02-14
Mibew Messenger MEDIUM 6.0
CVE-2012-0829

Multiple cross-site request forgery (CSRF) vulnerabilities in Mibew Messenger 1.6.4 and earlier allow remote attackers to hijack the authentication o…

Fix: after 1.6.4
Fix from $1,600 2012-02-14
Forward MEDIUM 6.0
CVE-2012-1057

Cross-site request forgery (CSRF) vulnerability in the clickthrough tracking functionality in the Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x …

Patch available
Fix from $1,600 2012-02-14
Flyspray MEDIUM 6.0
CVE-2012-1058

Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requests that …

No fix yet
Fix from $1,600 2012-02-14
Pocket Wifi Firmware MEDIUM 6.8
CVE-2012-0314

Multiple cross-site request forgery (CSRF) vulnerabilities on the eAccess Pocket WiFi (aka GP02) router before 2.00 with firmware 11.203.11.05.168 an…

Fix: after 11.203.11.05.168
Fix from $1,600 2012-02-03
Bugzilla MEDIUM 5.1
CVE-2012-0440

Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and …

Patch available
Fix from $1,600 2012-02-02
Support Incident Tracker MEDIUM 6.8
CVE-2011-5074

Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijack the au…

Fix: after 3.64
Fix from $1,600 2012-01-29
Support Incident Tracker MEDIUM 6.8
CVE-2011-5068

Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to hijack the authentic…

Mitigation only
Fix from $1,600 2012-01-29