Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Gate2 Plus Wi Fi MEDIUM 6.8
CVE-2008-7165

Cross-site request forgery in cp06_wifi_m_nocifr.cgi in the administrator panel in TELECOM ITALIA Alice Gate2 Plus Wi-Fi allows remote attackers to h…

No fix yet
Fix from $1,600 2009-09-04
Eye Fi Manager MEDIUM 6.8
CVE-2008-7139

Multiple cross-site request forgery (CSRF) vulnerabilities in WS-Proxy in Eye-Fi 1.1.2 allow remote attackers to hijack the authentication of users f…

No fix yet
Fix from $1,600 2009-09-01
Live MEDIUM 6.8
CVE-2008-7151

Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication…

Patch available
Fix from $1,600 2009-09-01
Bingo\!cms MEDIUM 6.5
CVE-2009-3022

Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for …

Fix: after 1.2
Fix from $1,600 2009-08-31
Squirrelmail MEDIUM 6.8
CVE-2009-2964

Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and earlier, and NaSMail before 1.7, allow remote attackers to hija…

Fix: after 1.4.19
Fix from $1,600 2009-08-25
Mybb MEDIUM 6.8
CVE-2008-7082

MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) d…

Mitigation only
Fix from $1,600 2009-08-25
Bandsite Cms MEDIUM 6.8
CVE-2008-7058

Cross-site request forgery (CSRF) vulnerability in BandSite CMS 1.1.4 allows remote attackers to hijack the authentication of administrators and forc…

No fix yet
Fix from $1,600 2009-08-24
Big Ip MEDIUM 6.8
CVE-2008-7032

Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hi…

No fix yet
Fix from $1,600 2009-08-24
Tnftpd MEDIUM 6.8
CVE-2008-7016

tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF…

Mitigation only
Fix from $1,600 2009-08-21
Dd Wrt MEDIUM 6.8
CVE-2008-6974

Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp1 and earlier allow remote attackers to hijack the authenticat…

Fix: after 24
Fix from $1,600 2009-08-14
Dd Wrt MEDIUM 6.8
CVE-2008-6975

Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authentication of admin…

No fix yet
Fix from $1,600 2009-08-14
Insight Control Suite For Linux MEDIUM 6.8
CVE-2009-2677

Cross-site request forgery (CSRF) vulnerability in HP Insight Control Suite For Linux (aka ICE-LX) before 2.11 allows remote attackers to hijack the …

Fix: after 2.10
Fix from $1,600 2009-08-14
Collabtive MEDIUM 6.8
CVE-2008-6949

Multiple cross-site request forgery (CSRF) vulnerabilities in Collabtive 0.4.8 allow remote attackers to hijack the authentication of administrators …

No fix yet
Fix from $1,600 2009-08-12
Babbleboard MEDIUM 6.0
CVE-2008-6905

Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to hijack the authentication of a…

No fix yet
Fix from $1,600 2009-08-06
Fivestar Module For Drupal MEDIUM 6.8
CVE-2009-2572

Cross-site request forgery (CSRF) vulnerability in the Fivestar module 5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for Drupal, allo…

Patch available
Fix from $1,600 2009-07-22
Mv 410r MEDIUM 5.8
CVE-2009-2323

The web interface on the Axesstel MV 410R redirects users back to the referring page after execution of some CGI scripts, which makes it easier for r…

Mitigation only
Fix from $1,600 2009-07-05
Openid MEDIUM 6.8
CVE-2008-6836

Cross-site request forgery (CSRF) vulnerability in OpenID 5.x before 5x.-1.2, a module for Drupal, allows remote attackers to hijack the authenticati…

Patch available
Fix from $1,600 2009-06-27
Campus Virtual Lms MEDIUM 6.8
CVE-2009-2150

Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack the authentication of arbitrary…

No fix yet
Fix from $1,600 2009-06-22
Elvinbts MEDIUM 6.8
CVE-2009-2129

Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authentication of arbitrary users v…

No fix yet
Fix from $1,600 2009-06-19
Wrt160n MEDIUM 6.8
CVE-2009-2073

Cross-site request forgery (CSRF) vulnerability in Linksys WRT160N wireless router hardware 1 and firmware 1.02.2 allows remote attackers to hijack t…

Mitigation only
Fix from $1,600 2009-06-15
Jira MEDIUM 6.8
CVE-2008-6832

Cross-site request forgery (CSRF) vulnerability in Atlassian JIRA Enterprise Edition 3.13 allows remote attackers to hijack the authentication of uns…

No fix yet
Fix from $1,600 2009-06-08
Dokeos MEDIUM 6.8
CVE-2009-2005

Cross-site request forgery (CSRF) vulnerability in Dokeos 1.8.5, and possibly earlier, allows remote attackers to hijack the authentication of unspec…

Patch available
Fix from $1,600 2009-06-08
Wl54ap2 MEDIUM 6.8
CVE-2008-6823

Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2 access points before firmwar…

Fix: after 1.4.1
Fix from $1,600 2009-06-04
Freepbx MEDIUM 6.8
CVE-2009-1802

Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote att…

Patch available
Fix from $1,600 2009-05-28
Transmission MEDIUM 6.8
CVE-2009-1757

Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authenticat…

Patch available
Fix from $1,600 2009-05-22
Ipplan MEDIUM 6.8
CVE-2009-1733

Cross-site request forgery (CSRF) vulnerability in IPplan 4.91a allows remote attackers to hijack the authentication of administrators for requests t…

Mitigation only
Fix from $1,600 2009-05-20
Application Access Server MEDIUM 6.8
CVE-2009-1464

Multiple cross-site request forgery (CSRF) vulnerabilities in index.aas in Application Access Server (A-A-S) 2.0.48 allow remote attackers to hijack …

No fix yet
Fix from $1,600 2009-05-14
Wrt54gc MEDIUM 6.8
CVE-2009-1561

Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware 1.05.7 allows remote attacker…

No fix yet
Fix from $1,600 2009-05-06
Beltane MEDIUM 6.8
CVE-2009-1518

Cross-site request forgery (CSRF) vulnerability in Beltane before 2.3.11 allows remote attackers to hijack the authentication of unspecified victims …

Fix: after 2.3.9
Fix from $1,600 2009-05-04
Twiki MEDIUM 6.0
CVE-2009-1339

Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbitrary use…

Fix: after 4.3.0
Fix from $1,600 2009-04-30