Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Foswiki MEDIUM 6.8
CVE-2009-1434

Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary users for r…

Fix: after 1.0.4
Fix from $1,600 2009-04-30
Viart Shop MEDIUM 6.8
CVE-2008-6758

Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authenti…

No fix yet
Fix from $1,600 2009-04-28
Webcollab MEDIUM 6.8
CVE-2009-1455

Multiple cross-site request forgery (CSRF) vulnerabilities in WebCollab before 2.50 (aka Billy Goat) allow remote attackers to hijack the authenticat…

Patch available
Fix from $1,600 2009-04-28
Razorcms MEDIUM 6.8
CVE-2009-1459

Cross-site request forgery (CSRF) vulnerability in razorCMS before 0.4 allows remote attackers to hijack the authentication of administrators for req…

Fix: after 0.3
Fix from $1,600 2009-04-28
Cybozu Dezie MEDIUM 6.8
CVE-2008-6744

Cross-site request forgery (CSRF) vulnerability in Cybozu Office 6, Cybozu Dezie before 6.0(1.0), and Cybozu Garoon 2.0.0 through 2.1.3 allows remote…

Fix: after 6
Fix from $1,600 2009-04-23
Phpmotion MEDIUM 6.8
CVE-2008-6729

Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote attackers to hijack the authenti…

Fix: after 2.1
Fix from $1,600 2009-04-20
Geronimo MEDIUM 6.8
CVE-2009-0039EPSS 11%

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 …

No fix yet
Fix from $1,600 2009-04-17
Advanced Management Module MEDIUM 6.8
CVE-2009-1290

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM Bla…

No fix yet
Fix from $1,600 2009-04-13
Joomla MEDIUM 6.8
CVE-2009-1280

Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla! 1.5.x through 1.5.9 allow remote attackers to hijac…

Mitigation only
Fix from $1,600 2009-04-09
Simple Machines Forum MEDIUM 6.8
CVE-2008-6657

Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote atta…

No fix yet
Fix from $1,600 2009-04-07
Ajaxplorer MEDIUM 6.8
CVE-2008-6639

Cross-site request forgery (CSRF) vulnerability in admin.php in AjaXplorer 2.3.3 and 2.3.4 allows remote attackers to hijack the authentication of ad…

No fix yet
Fix from $1,600 2009-04-07
1701hg MEDIUM 6.8
CVE-2008-6605

Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 1701HG, 1800HW, 2071HG, and 270…

No fix yet
Fix from $1,600 2009-04-06
Torrentflux MEDIUM 6.8
CVE-2008-6585

Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack the authentication of administ…

No fix yet
Fix from $1,600 2009-04-03
Utorrent Webui MEDIUM 6.8
CVE-2008-6586

Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack the authent…

No fix yet
Fix from $1,600 2009-04-03
Vuze MEDIUM 6.8
CVE-2008-6587

Cross-site request forgery (CSRF) vulnerability in index.tmpl in Vuze (formerly Azureus HTML WebUI), probably 0.7.6, allows remote attackers to hijac…

No fix yet
Fix from $1,600 2009-04-03
Bugzilla MEDIUM 6.8
CVE-2009-1213

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote …

Patch available
Fix from $1,600 2009-04-01
Drupal MEDIUM 6.8
CVE-2008-6532

Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers …

Patch available
Fix from $1,600 2009-03-26
Plus1 MEDIUM 6.8
CVE-2009-1036

Cross-site request forgery (CSRF) vulnerability in the Plus 1 module before 6.x-2.6, a module for Drupal, allows remote attackers to cast votes for c…

Fix: after 6.x-2.5
Fix from $1,600 2009-03-20
Xampp MEDIUM 6.8
CVE-2008-6498

Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of …

No fix yet
Fix from $1,600 2009-03-20
Phpfox MEDIUM 6.8
CVE-2009-0969

Cross-site request forgery (CSRF) vulnerability in account/settings/account/index.php in phpFoX 1.6.21 allows remote attackers to hijack the authenti…

No fix yet
Fix from $1,600 2009-03-19
8100c Digital Sender MEDIUM 5.1
CVE-2009-0940

Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digita…

No fix yet
Fix from $1,600 2009-03-18
Virtuozzo Containers MEDIUM 6.8
CVE-2008-6478

Cross-site request forgery (CSRF) vulnerability in the file manager in the VZPP web interface for Parallels Virtuozzo 365.6.swsoft (build 4.0.0-365.6…

No fix yet
Fix from $1,600 2009-03-16
Parallels Virtuozzo MEDIUM 6.8
CVE-2008-6479

Cross-site request forgery (CSRF) vulnerability in the "change password" feature in the VZPP web interface for Parallels Virtuozzo 25.4.swsoft (build…

No fix yet
Fix from $1,600 2009-03-16
Datalife Engine MEDIUM 6.8
CVE-2008-6480

Cross-site request forgery (CSRF) vulnerability in engine/modules/imagepreview.php in Datalife Engine 6.7 allows remote attackers to hijack the authe…

Mitigation only
Fix from $1,600 2009-03-16
Curl MEDIUM 6.8
CVE-2009-0037EPSS 9%

The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which…

Patch available
Fix from $1,600 2009-03-05
Comment Mail MEDIUM 6.8
CVE-2008-6384

Multiple cross-site request forgery (CSRF) vulnerabilities in Comment Mail 5.x before 5.x-1.1, a module for Drupal, allow remote attackers to hijack …

Patch available
Fix from $1,600 2009-03-02
Streber MEDIUM 6.0
CVE-2008-6331

Multiple cross-site request forgery (CSRF) vulnerabilities in Streber before 0.08093 allow remote attackers to hijack the authentication of unspecifi…

Fix: after 0.0803
Fix from $1,600 2009-02-27
Openedit Digital Asset Management MEDIUM 6.8
CVE-2008-6239

Cross-site request forgery (CSRF) vulnerability in OpenEdit Digital Asset Management (DAM) before 5.2014 allows remote attackers to perform unspecifi…

Fix: after 5.0
Fix from $1,600 2009-02-23
Semanticscuttle MEDIUM 6.8
CVE-2009-0708

Multiple cross-site request forgery (CSRF) vulnerabilities in SemanticScuttle before 0.91 allow remote attackers to (1) hijack the authentication of …

Fix: after 0.90
Fix from $1,600 2009-02-23
Falt4 Extreme MEDIUM 6.8
CVE-2009-0648

Multiple cross-site request forgery (CSRF) vulnerabilities in the manage_users handler in admin/index.php in Falt4 CMS (aka Falt4 Extreme) RC4 allow …

No fix yet
Fix from $1,600 2009-02-19