Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.8 CVE-2008-7165 Cross-site request forgery in cp06_wifi_m_nocifr.cgi in the administrator panel in TELECOM ITALIA Alice Gate2 Plus Wi-Fi allows remote attackers to h… Gate2 Plus Wi Fi No fix yet Fix from $1,6002009-09-04 MEDIUM 6.8 CVE-2008-7139 Multiple cross-site request forgery (CSRF) vulnerabilities in WS-Proxy in Eye-Fi 1.1.2 allow remote attackers to hijack the authentication of users f… Eye Fi Manager No fix yet Fix from $1,6002009-09-01 MEDIUM 6.8 CVE-2008-7151 Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication… Live Patch available Fix from $1,6002009-09-01 MEDIUM 6.5 CVE-2009-3022 Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for … Bingo\!cms after 1.2 Fix from $1,6002009-08-31 MEDIUM 6.8 CVE-2009-2964 Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and earlier, and NaSMail before 1.7, allow remote attackers to hija… Squirrelmail after 1.4.19 Fix from $1,6002009-08-25 MEDIUM 6.8 CVE-2008-7082 MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) d… Mybb Mitigation only Fix from $1,6002009-08-25 MEDIUM 6.8 CVE-2008-7058 Cross-site request forgery (CSRF) vulnerability in BandSite CMS 1.1.4 allows remote attackers to hijack the authentication of administrators and forc… Bandsite Cms No fix yet Fix from $1,6002009-08-24 MEDIUM 6.8 CVE-2008-7032 Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hi… Big Ip No fix yet Fix from $1,6002009-08-24 MEDIUM 6.8 CVE-2008-7016 tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF… Tnftpd Mitigation only Fix from $1,6002009-08-21 MEDIUM 6.8 CVE-2008-6974 Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp1 and earlier allow remote attackers to hijack the authenticat… Dd Wrt after 24 Fix from $1,6002009-08-14 MEDIUM 6.8 CVE-2008-6975 Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authentication of admin… Dd Wrt No fix yet Fix from $1,6002009-08-14 MEDIUM 6.8 CVE-2009-2677 Cross-site request forgery (CSRF) vulnerability in HP Insight Control Suite For Linux (aka ICE-LX) before 2.11 allows remote attackers to hijack the … Insight Control Suite For Linux after 2.10 Fix from $1,6002009-08-14 MEDIUM 6.8 CVE-2008-6949 Multiple cross-site request forgery (CSRF) vulnerabilities in Collabtive 0.4.8 allow remote attackers to hijack the authentication of administrators … Collabtive No fix yet Fix from $1,6002009-08-12 MEDIUM 6.0 CVE-2008-6905 Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to hijack the authentication of a… Babbleboard No fix yet Fix from $1,6002009-08-06 MEDIUM 6.8 CVE-2009-2572 Cross-site request forgery (CSRF) vulnerability in the Fivestar module 5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for Drupal, allo… Fivestar Module For Drupal Patch available Fix from $1,6002009-07-22 MEDIUM 5.8 CVE-2009-2323 The web interface on the Axesstel MV 410R redirects users back to the referring page after execution of some CGI scripts, which makes it easier for r… Mv 410r Mitigation only Fix from $1,6002009-07-05 MEDIUM 6.8 CVE-2008-6836 Cross-site request forgery (CSRF) vulnerability in OpenID 5.x before 5x.-1.2, a module for Drupal, allows remote attackers to hijack the authenticati… Openid Patch available Fix from $1,6002009-06-27 MEDIUM 6.8 CVE-2009-2150 Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack the authentication of arbitrary… Campus Virtual Lms No fix yet Fix from $1,6002009-06-22 MEDIUM 6.8 CVE-2009-2129 Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authentication of arbitrary users v… Elvinbts No fix yet Fix from $1,6002009-06-19 MEDIUM 6.8 CVE-2009-2073 Cross-site request forgery (CSRF) vulnerability in Linksys WRT160N wireless router hardware 1 and firmware 1.02.2 allows remote attackers to hijack t… Wrt160n Mitigation only Fix from $1,6002009-06-15 MEDIUM 6.8 CVE-2008-6832 Cross-site request forgery (CSRF) vulnerability in Atlassian JIRA Enterprise Edition 3.13 allows remote attackers to hijack the authentication of uns… Jira No fix yet Fix from $1,6002009-06-08 MEDIUM 6.8 CVE-2009-2005 Cross-site request forgery (CSRF) vulnerability in Dokeos 1.8.5, and possibly earlier, allows remote attackers to hijack the authentication of unspec… Dokeos Patch available Fix from $1,6002009-06-08 MEDIUM 6.8 CVE-2008-6823 Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2 access points before firmwar… Wl54ap2 after 1.4.1 Fix from $1,6002009-06-04 MEDIUM 6.8 CVE-2009-1802 Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote att… Freepbx Patch available Fix from $1,6002009-05-28 MEDIUM 6.8 CVE-2009-1757 Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authenticat… Transmission Patch available Fix from $1,6002009-05-22 MEDIUM 6.8 CVE-2009-1733 Cross-site request forgery (CSRF) vulnerability in IPplan 4.91a allows remote attackers to hijack the authentication of administrators for requests t… Ipplan Mitigation only Fix from $1,6002009-05-20 MEDIUM 6.8 CVE-2009-1464 Multiple cross-site request forgery (CSRF) vulnerabilities in index.aas in Application Access Server (A-A-S) 2.0.48 allow remote attackers to hijack … Application Access Server No fix yet Fix from $1,6002009-05-14 MEDIUM 6.8 CVE-2009-1561 Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware 1.05.7 allows remote attacker… Wrt54gc No fix yet Fix from $1,6002009-05-06 MEDIUM 6.8 CVE-2009-1518 Cross-site request forgery (CSRF) vulnerability in Beltane before 2.3.11 allows remote attackers to hijack the authentication of unspecified victims … Beltane after 2.3.9 Fix from $1,6002009-05-04 MEDIUM 6.0 CVE-2009-1339 Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbitrary use… Twiki after 4.3.0 Fix from $1,6002009-04-30