Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,548 CVEs tagged with CWE-352146 Critical, 3,434 High, 5,777 Medium, 189 Low, 2 Unrated.

CVE-2012-2128

Published Aug 27, 2012

Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to hijack the authentication of administrators for requests that a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1921

Published Aug 26, 2012

Cross-site request forgery (CSRF) vulnerability in goform/admin/formWlEncrypt in Sitecom WLM-2501 allows remote attackers to hijack the authentication of administrators for reques…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5191

Published Aug 26, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities on the Blue Coat ProxyAV appliance before 3.2.6.1 allow remote attackers to hijack the authentication of administrators…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-5088

Published Aug 26, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in SilverStripe 2.3.x before 2.3.9 and 2.4.x before 2.4.3 allow remote attackers to hijack the authentication of adminis…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5080

Published Aug 26, 2012

The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a password through email, which…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2155

Published Aug 14, 2012

Cross-site request forgery (CSRF) vulnerability in the CDN2 Video module 6.x for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vec…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2077

Published Aug 14, 2012

Cross-site request forgery (CSRF) vulnerability in the ShareThis module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of users with admini…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4326

Published Aug 14, 2012

Cross-site request forgery (CSRF) vulnerability in commonsettings.php in AlstraSoft Site Uptime Enterprise, possibly 5.4, allows remote attackers to hijack the authentication of a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4325

Published Aug 14, 2012

Cross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and earlier allows remote attackers to hijack the authentication of administrato…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4324

Published Aug 14, 2012

Cross-site request forgery (CSRF) vulnerability in PHPJabbers Vacation Rental Script allows remote attackers to hijack the authentication of administrators for requests that add a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2097

Published Aug 14, 2012

Cross-site request forgery (CSRF) vulnerability in the Autosave module 6.x before 6.x-2.10 and 7.x-2.x before 7.x-2.0 for Drupal allows remote attackers to hijack the authenticati…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4280

Published Aug 13, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in admin/agenteditor.php in Free Realty 3.1-0.6 allow remote attackers to hijack the authentication of administrators fo…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4252

Published Aug 13, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the authentication of administrators for requests that (1) remove…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4059

Published Jul 25, 2012

Cross-site request forgery (CSRF) vulnerability in home/secretqtn.php in SocketMail Pro 2.2.9 allows remote attackers to hijack the authentication of arbitrary users for requests…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2307

Published Jul 25, 2012

Cross-site request forgery (CSRF) vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to hijack the authentication of unspecified victim…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2305

Published Jul 25, 2012

Cross-site request forgery (CSRF) vulnerability in the Node Gallery module for Drupal 6.x-3.1 and earlier allows remote attackers to hijack the authentication of certain users for…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4053

Published Jul 25, 2012

Cross-site request forgery (CSRF) vulnerability in eZOE flash player in eZ Publish 4.1 through 4.6 allows remote attackers to hijack the authentication of unspecified victims via…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3384

Published Jul 22, 2012

Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4281

Published Jul 16, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitrary users for requests that ma…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4133

Published Jul 16, 2012

Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3362

Published Jul 12, 2012

Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an ad…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4298

Published Jul 11, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authent…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 9,101-9,125 of 9,548 CVEsPage 365 of 382