Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Rateme MEDIUM 6.8
CVE-2008-4899

Cross-site request forgery (CSRF) vulnerability in Planetluc RateMe 1.3.3 allows remote attackers to perform unauthorized actions as other users via …

Mitigation only
Fix from $1,600 2008-11-04
Interact MEDIUM 6.8
CVE-2008-3868

Cross-site request forgery (CSRF) vulnerability in Interact 2.4.1 allows remote attackers to hijack the authentication of super administrators for re…

Mitigation only
Fix from $1,600 2008-11-03
Wp Comment Remix Plugin HIGH 7.5
CVE-2008-4734

Cross-site request forgery (CSRF) vulnerability in the wpcr_do_options_page function in WP Comment Remix plugin before 1.4.4 for WordPress allows rem…

Fix: after 1.4.3
Fix from $1,950 2008-10-24
H Sphere MEDIUM 6.8
CVE-2008-4448

Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perform unaut…

No fix yet
Fix from $1,600 2008-10-06
Proftpd MEDIUM 6.8
CVE-2008-4242EPSS 7%

ProFTPD 1.3.1 interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (…

No fix yet
Fix from $1,600 2008-09-25
FreeBSD HIGH 7.5
CVE-2008-4247

ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple c…

No fix yet
Fix from $1,950 2008-09-25
iOS HIGH 9.3
CVE-2008-4128EPSS 33%

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Rout…

No fix yet
Fix from $1,950 2008-09-18
Opendb HIGH 8.8
CVE-2008-3938

Cross-site request forgery (CSRF) vulnerability in user_admin.php in Open Media Collectors Database (OpenDb) 1.0.6 allows remote attackers to change …

No fix yet
Fix from $1,950 2008-09-05
Django MEDIUM 5.8
CVE-2008-3909

The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentic…

Fix: 0.91.3 / 0.95.4+
Fix from $1,600 2008-09-04
Blogn MEDIUM 6.8
CVE-2008-3885

Cross-site request forgery (CSRF) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to hijack the authentication of arbitra…

Fix: after 1.9.7
Fix from $1,600 2008-09-02
Lacoodast MEDIUM 6.0
CVE-2008-3736

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 …

Fix: after 2.1.3
Fix from $1,600 2008-08-27
Drupal MEDIUM 5.8
CVE-2008-3743

Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions vi…

Mitigation only
Fix from $1,600 2008-08-27
Drupal MEDIUM 5.8
CVE-2008-3744

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authenti…

Patch available
Fix from $1,600 2008-08-27
Vanilla HIGH 7.5
CVE-2008-3759

Cross-site request forgery (CSRF) vulnerability in ajax/UpdateCheck.php in Vanilla 1.1.4 and earlier has unknown impact and remote attack vectors.

Fix: after 1.1.4
Fix from $1,950 2008-08-21
Harmoni MEDIUM 6.0
CVE-2008-3716

Cross-site request forgery (CSRF) vulnerability in Harmoni before 1.6.0 allows remote attackers to make administrative modifications via a (1) save o…

Fix: after 1.4.7
Fix from $1,600 2008-08-19
Web Wiz Forum MEDIUM 5.8
CVE-2008-3392

Cross-site request forgery (CSRF) vulnerability in Web Wiz Forum 9.5 allows remote attackers to log out a user via a link or IMG tag to log_off_user.…

No fix yet
Fix from $1,600 2008-07-31
Moodle MEDIUM 6.0
CVE-2008-3325

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile setting…

Fix: 1.6.7 / 1.7.5+
Fix from $1,600 2008-07-25
Claroline MEDIUM 5.8
CVE-2008-3262

Cross-site request forgery (CSRF) vulnerability in Claroline before 1.8.10 allows remote attackers to change passwords, related to lack of a requirem…

Fix: after 1.8.9
Fix from $1,600 2008-07-22
Mybloggie MEDIUM 5.1
CVE-2008-3080

Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administ…

No fix yet
Fix from $1,600 2008-07-09
Client HIGH 7.1
CVE-2008-1106

The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request…

Fix: after 3322
Fix from $1,950 2008-06-09
Mantis MEDIUM 6.8
CVE-2008-2276

Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to create new administrative users …

No fix yet
Fix from $1,600 2008-05-16
Surfboard HIGH 7.8
CVE-2008-2002

Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1…

No fix yet
Fix from $1,950 2008-04-28
E Publish MEDIUM 6.8
CVE-2008-1981

Cross-site request forgery (CSRF) vulnerability in E-Publish 5.x before 5.x-1.1 and 6.x before 6.x-1.0 beta1, a Drupal module, allows remote attacker…

Patch available
Fix from $1,600 2008-04-27
Nuke Et MEDIUM 6.8
CVE-2008-1719

Multiple cross-site request forgery (CSRF) vulnerabilities in Nuke ET 3.2 and 3.4 allow remote attackers to perform actions as administrators, as dem…

Mitigation only
Fix from $1,600 2008-04-10
Burning Board Lite MEDIUM 6.8
CVE-2008-1323

Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board Lite (wBB) 2 Beta 1 allows remote attackers to delete threads a…

No fix yet
Fix from $1,600 2008-03-13
320 Sip Phone MEDIUM 5.8
CVE-2008-1248

The web interface on the central phone server for the Snom 320 SIP Phone allows remote attackers to make arbitrary phone calls via the "Call a number…

No fix yet
Fix from $1,600 2008-03-10
320 Sip Phone HIGH 9.3
CVE-2008-1250

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the central phone server for the Snom 320 SIP Phone allow remote a…

Mitigation only
Fix from $1,950 2008-03-10
P 660hw MEDIUM 6.8
CVE-2008-1254

Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2…

No fix yet
Fix from $1,600 2008-03-10
phpMyAdmin MEDIUM 5.1
CVE-2008-1149

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to overr…

Fix: after 2.11.4
Fix from $1,600 2008-03-04
Openca Pki HIGH 7.5
CVE-2008-0556

Cross-site request forgery (CSRF) vulnerability in OpenCA PKI 0.9.2.5, and possibly earlier versions, allows remote attackers to perform unauthorized…

Fix: after 0.9.2.5
Fix from $1,950 2008-02-19