Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Webgui MEDIUM 6.8
CVE-2009-4877

Multiple cross-site request forgery (CSRF) vulnerabilities in WebGUI before 7.7.14 allow remote attackers to hijack the authentication of users for u…

Fix: after 7.7.13
Fix from $1,600 2010-05-26
Gpeasy Cms MEDIUM 6.8
CVE-2010-2039

Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of admin…

Fix: after 1.6.2
Fix from $1,600 2010-05-25
Ctools MEDIUM 6.8
CVE-2010-1547

Multiple cross-site request forgery (CSRF) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote att…

Patch available
Fix from $1,600 2010-05-21
Letodms MEDIUM 6.8
CVE-2010-2007

Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) 1.7.2 and earlier allow remote attackers to hijack the authent…

Fix: after 1.7.2
Fix from $1,600 2010-05-20
Virtualiq MEDIUM 6.8
CVE-2009-4849

Multiple cross-site request forgery (CSRF) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers to h…

No fix yet
Fix from $1,600 2010-05-07
Zikula Application Framework MEDIUM 6.8
CVE-2010-1732

Cross-site request forgery (CSRF) vulnerability in the users module in Zikula Application Framework before 1.2.3 allows remote attackers to hijack th…

Fix: after 1.2.2
Fix from $1,600 2010-05-06
Opencart MEDIUM 6.8
CVE-2010-1610

Cross-site request forgery (CSRF) vulnerability in index.php in OpenCart 1.4 allows remote attackers to hijack the authentication of an application a…

Mitigation only
Fix from $1,600 2010-04-29
Alegrocart MEDIUM 6.8
CVE-2010-1611

Cross-site request forgery (CSRF) vulnerability in AlegroCart 1.1 allows remote attackers to hijack the authentication of the administrator for reque…

Patch available
Fix from $1,600 2010-04-29
Systems Insight Manager MEDIUM 6.8
CVE-2010-1037

Cross-site request forgery (CSRF) vulnerability in HP System Insight Manager before 6.0 allows remote attackers to hijack the authentication of unspe…

Fix: after 5.2
Fix from $1,600 2010-04-28
Mini Hosting Panel MEDIUM 6.8
CVE-2009-4826

Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authent…

No fix yet
Fix from $1,600 2010-04-27
Mail Manager Pro MEDIUM 6.8
CVE-2009-4827

Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the authentication of administrato…

No fix yet
Fix from $1,600 2010-04-27
Ad Manager Pro MEDIUM 6.8
CVE-2009-4828

Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 allows remote attackers to hija…

No fix yet
Fix from $1,600 2010-04-27
Dfd Cart MEDIUM 6.8
CVE-2010-1542

Multiple cross-site request forgery (CSRF) vulnerabilities in admin/configure.php in DFD Cart 1.198, 1.197, and earlier allow remote attackers to hij…

Fix: after 1.198
Fix from $1,600 2010-04-26
Pligg Cms MEDIUM 6.8
CVE-2009-4787

Multiple cross-site request forgery (CSRF) vulnerabilities in Pligg before 1.0.3 allow remote attackers to hijack the authentication of administrator…

Fix: after 1.0.2
Fix from $1,600 2010-04-21
Mediawiki MEDIUM 6.0
CVE-2010-1150

MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes i…

Fix: after 1.15.2
Fix from $1,600 2010-04-20
Ubercart MEDIUM 6.8
CVE-2009-4773

Cross-site request forgery (CSRF) vulnerability in the order-management functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.…

Patch available
Fix from $1,600 2010-04-20
Pulse Cms MEDIUM 6.8
CVE-2010-0992

Multiple cross-site request forgery (CSRF) vulnerabilities in Pulse CMS Basic 1.2.2 and 1.2.3, and possibly Pulse Pro before 1.3.2, allow remote atta…

Patch available
Fix from $1,600 2010-04-09
Activemq MEDIUM 6.8
CVE-2010-1244

Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the aut…

Fix: after 5.3.0
Fix from $1,600 2010-04-05
Lotus Inotes MEDIUM 6.8
CVE-2010-0921

Cross-site request forgery (CSRF) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote …

Fix: after 229.271
Fix from $1,600 2010-03-03
Zenoss MEDIUM 6.8
CVE-2010-0713

Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authe…

Fix: after 2.4.5
Fix from $1,600 2010-02-26
Limny MEDIUM 6.8
CVE-2010-0709

Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authentication of users or administr…

Patch available
Fix from $1,600 2010-02-25
Aspcode Cms MEDIUM 6.8
CVE-2010-0711

Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote atta…

No fix yet
Fix from $1,600 2010-02-25
Employee Timeclock Software MEDIUM 6.8
CVE-2010-0707

Cross-site request forgery (CSRF) vulnerability in add_user.php in Employee Timeclock Software 0.99 allows remote attackers to hijack the authenticat…

No fix yet
Fix from $1,600 2010-02-25
Dokuwiki MEDIUM 6.8
CVE-2010-0289

Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remo…

Mitigation only
Fix from $1,600 2010-02-15
Webcalendar MEDIUM 6.8
CVE-2010-0638

Cross-site request forgery (CSRF) vulnerability in WebCalendar 1.2.0 allows remote attackers to hijack the authentication of administrators for reque…

Mitigation only
Fix from $1,600 2010-02-15
Webcalendar MEDIUM 6.8
CVE-2010-0637

Multiple cross-site request forgery (CSRF) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to hijack th…

Mitigation only
Fix from $1,600 2010-02-12
Phpshop MEDIUM 6.8
CVE-2009-4572

Cross-site request forgery (CSRF) vulnerability in PhpShop 0.8.1 allows remote attackers to hijack the authentication of arbitrary users for requests…

No fix yet
Fix from $1,600 2010-01-05
Agoracart MEDIUM 6.8
CVE-2009-4555

Multiple cross-site request forgery (CSRF) vulnerabilities in AgoraCart 5.2.005 and 5.2.006 and AgoraCart GOLD 5.5.005 allow remote attackers to hija…

Mitigation only
Fix from $1,600 2010-01-04
Faq Ask MEDIUM 6.8
CVE-2009-4517

Cross-site request forgery (CSRF) vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to hij…

Patch available
Fix from $1,600 2009-12-31
Network Management Card MEDIUM 6.8
CVE-2009-1797

Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU …

Mitigation only
Fix from $1,600 2009-12-28