Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,429 CVEs tagged with CWE-352140 Critical, 3,377 High, 5,723 Medium, 183 Low, 6 Unrated.

CVE-2008-3909

Published Sep 4, 2008

The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows rem…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3885

Published Sep 2, 2008

Cross-site request forgery (CSRF) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that mak…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3743

Published Aug 27, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3744

Published Aug 27, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for r…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3759

Published Aug 21, 2008

Cross-site request forgery (CSRF) vulnerability in ajax/UpdateCheck.php in Vanilla 1.1.4 and earlier has unknown impact and remote attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3760

Published Aug 21, 2008

Cross-site request forgery (CSRF) vulnerability in the sign-out page in Vanilla 1.1.4 and earlier allows remote attackers to hijack the authentication of arbitrary users for reque…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3716

Published Aug 19, 2008

Cross-site request forgery (CSRF) vulnerability in Harmoni before 1.6.0 allows remote attackers to make administrative modifications via a (1) save or (2) delete action to an unsp…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3421

Published Jul 31, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in Blackboard Academic Suite 8.0.260.7 allow remote attackers to hijack the authentication of student users for requests…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3392

Published Jul 31, 2008

Cross-site request forgery (CSRF) vulnerability in Web Wiz Forum 9.5 allows remote attackers to log out a user via a link or IMG tag to log_off_user.asp.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3325

Published Jul 25, 2008

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3262

Published Jul 22, 2008

Cross-site request forgery (CSRF) vulnerability in Claroline before 1.8.10 allows remote attackers to change passwords, related to lack of a requirement for the previous password.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3220

Published Jul 18, 2008

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3221

Published Jul 18, 2008

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3197

Published Jul 16, 2008

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-3080

Published Jul 9, 2008

Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administrators. NOTE: this can be lev…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2531

Published Jun 3, 2008

Cross-site scripting (XSS) vulnerability in the search script in Build A Niche Store (BANS) 3.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2276

Published May 16, 2008

Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to create new administrative users via a crafted link.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2140

Published May 12, 2008

Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to reset the root password as the administra…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-2071

Published May 12, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in the WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allow remote attackers to perform…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2043

Published May 1, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in cPanel, possibly 11.18.3 and 11.19.3, allow remote attackers to (1) execute arbitrary code via the command1 parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2002

Published Apr 28, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1) cause a denial of service (d…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1981

Published Apr 27, 2008

Cross-site request forgery (CSRF) vulnerability in E-Publish 5.x before 5.x-1.1 and 6.x before 6.x-1.0 beta1, a Drupal module, allows remote attackers to perform unauthorized acti…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 9,326-9,350 of 9,429 CVEsPage 374 of 378