Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.8 CVE-2008-4899 Cross-site request forgery (CSRF) vulnerability in Planetluc RateMe 1.3.3 allows remote attackers to perform unauthorized actions as other users via … Rateme Mitigation only Fix from $1,6002008-11-04 MEDIUM 6.8 CVE-2008-3868 Cross-site request forgery (CSRF) vulnerability in Interact 2.4.1 allows remote attackers to hijack the authentication of super administrators for re… Interact Mitigation only Fix from $1,6002008-11-03 HIGH 7.5 CVE-2008-4734 Cross-site request forgery (CSRF) vulnerability in the wpcr_do_options_page function in WP Comment Remix plugin before 1.4.4 for WordPress allows rem… Wp Comment Remix Plugin after 1.4.3 Fix from $1,9502008-10-24 MEDIUM 6.8 CVE-2008-4448 Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perform unaut… H Sphere No fix yet Fix from $1,6002008-10-06 MEDIUM 6.8 CVE-2008-4242EPSS 7% ProFTPD 1.3.1 interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (… Proftpd No fix yet Fix from $1,6002008-09-25 HIGH 7.5 CVE-2008-4247 ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple c… FreeBSD No fix yet Fix from $1,9502008-09-25 HIGH 9.3 CVE-2008-4128EPSS 33% Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Rout… iOS No fix yet Fix from $1,9502008-09-18 HIGH 8.8 CVE-2008-3938 Cross-site request forgery (CSRF) vulnerability in user_admin.php in Open Media Collectors Database (OpenDb) 1.0.6 allows remote attackers to change … Opendb No fix yet Fix from $1,9502008-09-05 MEDIUM 5.8 CVE-2008-3909 The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentic… Django 0.91.3 / 0.95.4+ Fix from $1,6002008-09-04 MEDIUM 6.8 CVE-2008-3885 Cross-site request forgery (CSRF) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to hijack the authentication of arbitra… Blogn after 1.9.7 Fix from $1,6002008-09-02 MEDIUM 6.0 CVE-2008-3736 Multiple cross-site request forgery (CSRF) vulnerabilities in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 … Lacoodast after 2.1.3 Fix from $1,6002008-08-27 MEDIUM 5.8 CVE-2008-3743 Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions vi… Drupal Mitigation only Fix from $1,6002008-08-27 MEDIUM 5.8 CVE-2008-3744 Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authenti… Drupal Patch available Fix from $1,6002008-08-27 HIGH 7.5 CVE-2008-3759 Cross-site request forgery (CSRF) vulnerability in ajax/UpdateCheck.php in Vanilla 1.1.4 and earlier has unknown impact and remote attack vectors. Vanilla after 1.1.4 Fix from $1,9502008-08-21 MEDIUM 6.0 CVE-2008-3716 Cross-site request forgery (CSRF) vulnerability in Harmoni before 1.6.0 allows remote attackers to make administrative modifications via a (1) save o… Harmoni after 1.4.7 Fix from $1,6002008-08-19 MEDIUM 5.8 CVE-2008-3392 Cross-site request forgery (CSRF) vulnerability in Web Wiz Forum 9.5 allows remote attackers to log out a user via a link or IMG tag to log_off_user.… Web Wiz Forum No fix yet Fix from $1,6002008-07-31 MEDIUM 6.0 CVE-2008-3325 Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile setting… Moodle 1.6.7 / 1.7.5+ Fix from $1,6002008-07-25 MEDIUM 5.8 CVE-2008-3262 Cross-site request forgery (CSRF) vulnerability in Claroline before 1.8.10 allows remote attackers to change passwords, related to lack of a requirem… Claroline after 1.8.9 Fix from $1,6002008-07-22 MEDIUM 5.1 CVE-2008-3080 Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administ… Mybloggie No fix yet Fix from $1,6002008-07-09 HIGH 7.1 CVE-2008-1106 The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request… Client after 3322 Fix from $1,9502008-06-09 MEDIUM 6.8 CVE-2008-2276 Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to create new administrative users … Mantis No fix yet Fix from $1,6002008-05-16 HIGH 7.8 CVE-2008-2002 Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1… Surfboard No fix yet Fix from $1,9502008-04-28 MEDIUM 6.8 CVE-2008-1981 Cross-site request forgery (CSRF) vulnerability in E-Publish 5.x before 5.x-1.1 and 6.x before 6.x-1.0 beta1, a Drupal module, allows remote attacker… E Publish Patch available Fix from $1,6002008-04-27 MEDIUM 6.8 CVE-2008-1719 Multiple cross-site request forgery (CSRF) vulnerabilities in Nuke ET 3.2 and 3.4 allow remote attackers to perform actions as administrators, as dem… Nuke Et Mitigation only Fix from $1,6002008-04-10 MEDIUM 6.8 CVE-2008-1323 Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board Lite (wBB) 2 Beta 1 allows remote attackers to delete threads a… Burning Board Lite No fix yet Fix from $1,6002008-03-13 MEDIUM 5.8 CVE-2008-1248 The web interface on the central phone server for the Snom 320 SIP Phone allows remote attackers to make arbitrary phone calls via the "Call a number… 320 Sip Phone No fix yet Fix from $1,6002008-03-10 HIGH 9.3 CVE-2008-1250 Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the central phone server for the Snom 320 SIP Phone allow remote a… 320 Sip Phone Mitigation only Fix from $1,9502008-03-10 MEDIUM 6.8 CVE-2008-1254 Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2… P 660hw No fix yet Fix from $1,6002008-03-10 MEDIUM 5.1 CVE-2008-1149 phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to overr… phpMyAdmin after 2.11.4 Fix from $1,6002008-03-04 HIGH 7.5 CVE-2008-0556 Cross-site request forgery (CSRF) vulnerability in OpenCA PKI 0.9.2.5, and possibly earlier versions, allows remote attackers to perform unauthorized… Openca Pki after 0.9.2.5 Fix from $1,9502008-02-19