Search Results (9632 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2014-1457 1 Openwebanalytics 1 Open Web Analytics 2024-11-21 N/A
Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protection mechanism by leveraging knowledge of an OWA user name.
CVE-2014-125028 1 Valtech 1 Idp Test Clients 2024-11-21 4.3 Medium
A vulnerability was found in valtech IDP Test Client and classified as problematic. Affected by this issue is some unknown functionality of the file python-flask/main.py. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The name of the patch is f1e7b3d431c8681ec46445557125890c14fa295f. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217148.
CVE-2014-10382 1 Pippinsplugins 1 Featured Comments 2024-11-21 N/A
The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.
CVE-2014-10381 1 User Domain Whitelist Project 1 User Domain Whitelist 2024-11-21 N/A
The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.
CVE-2014-0594 1 Opensuse 1 Open Build Service 2024-11-21 N/A
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
CVE-2014-0197 1 Redhat 3 Cloudforms, Cloudforms Management Engine, Cloudforms Managementengine 2024-11-21 8.8 High
CFME: CSRF protection vulnerability via permissive check of the referrer header
CVE-2014-0026 1 Redhat 1 Subscription Asset Manager 2024-11-21 6.5 Medium
katello-headpin is vulnerable to CSRF in REST API
CVE-2013-7464 1 Csrf-magic Project 1 Csrf-magic 2024-11-21 N/A
In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.
CVE-2013-6365 3 Debian, Horde, Opensuse 3 Debian Linux, Groupware, Opensuse 2024-11-21 5.3 Medium
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
CVE-2013-6364 2 Debian, Horde 2 Debian Linux, Groupware 2024-11-21 8.8 High
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
CVE-2013-6275 2 Debian, Horde 2 Debian Linux, Groupware 2024-11-21 6.5 Medium
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
CVE-2013-4665 1 Spbas 1 Business Automation Software 2024-11-21 6.5 Medium
SPBAS Business Automation Software 2012 has CSRF.
CVE-2013-3935 1 Opsview 2 Opsview, Opsview Core 2024-11-21 8.8 High
Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors.
CVE-2013-3568 1 Cisco 2 Linksys Wrt110, Linksys Wrt110 Firmware 2024-11-21 8.8 High
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
CVE-2013-3516 1 Netgear 4 Wnr3500l, Wnr3500l Firmware, Wnr3500u and 1 more 2024-11-21 6.5 Medium
NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens.
CVE-2013-3366 1 Trendnet 2 Tew-812dru, Tew-812dru Firmware 2024-11-21 8.8 High
Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3.
CVE-2013-3312 1 Loftek 2 Nexus 543, Nexus 543 Firmware 2024-11-21 8.8 High
Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewall configuration, as demonstrated by a request to set_users.cgi.
CVE-2013-3093 1 Asus 14 Dsl-n55u, Dsl-n55u Firmware, Rt-ac66u and 11 more 2024-11-21 8.8 High
ASUS RT-N56U devices allow CSRF.
CVE-2013-2109 1 Undolog 1 Wp Cleanfix 2024-11-21 8.8 High
WordPress plugin wp-cleanfix has Remote Code Execution
CVE-2013-2108 1 Undolog 1 Cleanfix 2024-11-21 5.4 Medium
WordPress WP Cleanfix Plugin 2.4.4 has CSRF