Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,429 CVEs tagged with CWE-352140 Critical, 3,377 High, 5,723 Medium, 183 Low, 6 Unrated.

CVE-2008-0165

Published Apr 21, 2008

Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1719

Published Apr 10, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in Nuke ET 3.2 and 3.4 allow remote attackers to perform actions as administrators, as demonstrated by inserting an XSS…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1654

Published Apr 2, 2008

Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by usi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0164

Published Mar 20, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote attackers to (1) add arbitrary accounts via the join_form page and (2) change…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6708

Published Mar 13, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware allow remote attackers to perform…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1323

Published Mar 13, 2008

Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board Lite (wBB) 2 Beta 1 allows remote attackers to delete threads as other users via the ThreadDe…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1248

Published Mar 10, 2008

The web interface on the central phone server for the Snom 320 SIP Phone allows remote attackers to make arbitrary phone calls via the "Call a number" field. NOTE: this might ove…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1250

Published Mar 10, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the central phone server for the Snom 320 SIP Phone allow remote attackers to perform actions as…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1254

Published Mar 10, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2) add keywords to the "bannedl…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1260

Published Mar 10, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities on the Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware allow remote attackers to (1) make the admin web server avail…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1149

Published Mar 4, 2008

phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and cond…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0556

Published Feb 19, 2008

Cross-site request forgery (CSRF) vulnerability in OpenCA PKI 0.9.2.5, and possibly earlier versions, allows remote attackers to perform unauthorized actions as authorized users v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0788

Published Feb 15, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and earlier allow remote attackers to (1) hijack the authentication of moderators or administrators for r…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0571

Published Feb 5, 2008

The point moderation form in the Userpoints 4.7.x before 4.7.x-2.3, 5.x-2 before 5.x-2.16, and 5.x-3 before 5.x-3.3 module for Drupal does not follow Drupal's Forms API submission…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0575

Published Feb 5, 2008

Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmin privilege level to arbitrary accounts…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0182

Published Feb 5, 2008

Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0563

Published Feb 5, 2008

Cross-site request forgery (CSRF) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to perform unspecified actions as unspeci…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0508

Published Jan 31, 2008

Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows remote attackers to modify the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0524

Published Jan 31, 2008

Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change password settings and probably o…

CVSS 7.5 · High

CVE-2008-0471

Published Jan 29, 2008

Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0472

Published Jan 29, 2008

Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0336

Published Jan 17, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in BugTracker.NET before 2.7.2 allow remote attackers to delete arbitrary bugs and perform other administrative tasks vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0266

Published Jan 15, 2008

Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administra…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-0271

Published Jan 15, 2008

The editor deletion form in BUEditor 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.1, a module for Drupal, does not follow Drupal's Forms API submission model, which allows remote a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 9,351-9,375 of 9,429 CVEsPage 375 of 378