Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Localization Client MEDIUM 6.8
CVE-2008-6169

Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x …

Fix: after 6.x-1.5
Fix from $1,600 2009-02-19
Workplace For Business Controls And Reporting MEDIUM 6.8
CVE-2008-6106

Cross-site request forgery (CSRF) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x…

No fix yet
Fix from $1,600 2009-02-10
Profense Web Application Firewall MEDIUM 6.8
CVE-2009-0468

Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allow remote attackers t…

No fix yet
Fix from $1,600 2009-02-10
Moodle MEDIUM 6.4
CVE-2009-0499

Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote at…

Mitigation only
Fix from $1,600 2009-02-10
Bugzilla MEDIUM 5.8
CVE-2009-0482

Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote at…

Mitigation only
Fix from $1,600 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0483

Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remot…

Mitigation only
Fix from $1,600 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0484

Cross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delet…

Mitigation only
Fix from $1,600 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0485

Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote at…

Mitigation only
Fix from $1,600 2009-02-09
Bugzilla HIGH 7.5
CVE-2009-0486

Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the sam…

Mitigation only
Fix from $1,950 2009-02-09
iOS MEDIUM 6.8
CVE-2009-0471

Cross-site request forgery (CSRF) vulnerability in the HTTP server in Cisco IOS 12.4(23) allows remote attackers to execute arbitrary commands, as de…

Mitigation only
Fix from $1,600 2009-02-06
Tangocms MEDIUM 6.0
CVE-2008-6048

Multiple cross-site request forgery (CSRF) vulnerabilities in TangoCMS before 2.2.0 allow remote attackers to hijack the authentication of administra…

Fix: after 2.1.2
Fix from $1,600 2009-02-04
Oscommerce MEDIUM 6.0
CVE-2009-0408

Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote attackers to hijack the authentication of administrators.

Mitigation only
Fix from $1,600 2009-02-03
Groupwise MEDIUM 6.8
CVE-2009-0272

Cross-site request forgery (CSRF) vulnerability in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allows remote attackers…

Mitigation only
Fix from $1,600 2009-02-02
Modxcms MEDIUM 6.0
CVE-2008-5941

Cross-site request forgery (CSRF) vulnerability in MODx 0.9.6.1p2 and earlier allows remote attackers to perform unauthorized actions as other users …

Fix: after 0.9.6.1
Fix from $1,600 2009-01-22
Ironport Encryption Appliance MEDIUM 6.8
CVE-2009-0055

Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5,…

Mitigation only
Fix from $1,600 2009-01-16
Ironport Encryption Appliance MEDIUM 6.8
CVE-2009-0056

Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5,…

Mitigation only
Fix from $1,600 2009-01-16
Poll Pro MEDIUM 6.8
CVE-2009-0112

Cross-site request forgery (CSRF) vulnerability in admin/agent_edit.asp in PollPro 3.0 allows remote attackers to create or modify accounts as admini…

No fix yet
Fix from $1,600 2009-01-09
Phparanoid MEDIUM 6.8
CVE-2008-5758

Cross-site request forgery (CSRF) vulnerability in PHParanoid before 0.5 allows remote attackers to perform unspecified actions as authenticated user…

Fix: after 0.4
Fix from $1,600 2008-12-30
Mediawiki MEDIUM 5.8
CVE-2008-5252

Cross-site request forgery (CSRF) vulnerability in the Special:Import feature in MediaWiki 1.3.0 through 1.6.10, 1.12.x before 1.12.2, and 1.13.x bef…

Patch available
Fix from $1,600 2008-12-19
Phparanoid MEDIUM 6.8
CVE-2008-5672

Multiple cross-site request forgery (CSRF) vulnerabilities in PHParanoid before 0.4 allow remote attackers to hijack the authentication of arbitrary …

Fix: after 0.3
Fix from $1,600 2008-12-19
phpMyAdmin MEDIUM 6.0
CVE-2008-5621

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauth…

Patch available
Fix from $1,600 2008-12-17
Dl Paycart MEDIUM 6.8
CVE-2008-5565

Cross-site request forgery (CSRF) vulnerability in admin/settings.php in DL PayCart 1.34 and earlier allows remote attackers to change the admin pass…

Fix: after 1.34
Fix from $1,600 2008-12-15
Bonza Cart MEDIUM 6.8
CVE-2008-5567

Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote attackers to change the admin p…

Fix: after 1.10
Fix from $1,600 2008-12-15
Ipn Pro 3 MEDIUM 6.8
CVE-2008-5568

Cross-site request forgery (CSRF) vulnerability in admin/settings.php in IPN Pro 3 1.44 and earlier allows remote attackers to change the admin passw…

Fix: after 1.44
Fix from $1,600 2008-12-15
Projectpier MEDIUM 6.8
CVE-2008-5583

Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as an administ…

Fix: after 0.8
Fix from $1,600 2008-12-15
Mvnforum MEDIUM 6.8
CVE-2008-5400

Multiple cross-site request forgery (CSRF) vulnerabilities in mvnForum before 1.2.1 GA allow remote attackers to (1) create forums, (2) change accoun…

Fix: after 1.2
Fix from $1,600 2008-12-10
Hlf F160 MEDIUM 6.8
CVE-2008-5382

Cross-site request forgery (CSRF) vulnerability in I-O DATA DEVICE HDL-F160, HDL-F250, HDL-F300, and HDL-F320 firmware before 1.02 allows remote atta…

Mitigation only
Fix from $1,600 2008-12-09
Rails MEDIUM 5.0
CVE-2008-5189

CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitti…

Fix: after 2.0.4
Fix from $1,600 2008-11-21
Java System Identity Manager MEDIUM 6.8
CVE-2008-5115

Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hija…

Patch available
Fix from $1,600 2008-11-18
Nagios MEDIUM 6.8
CVE-2008-5028

Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send comma…

Fix: after 4.0.0
Fix from $1,600 2008-11-10