Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,473 CVEs tagged with CWE-352144 Critical, 3,402 High, 5,736 Medium, 184 Low, 7 Unrated.

CVE-2011-0629

Published Jun 16, 2011

Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote attackers to hijack the authentication of unspecified victims via unkn…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1954

Published Jun 6, 2011

Multiple cross-site request forgery (CSRF) vulnerabilities in Post Revolution 0.8.0c-2 and earlier allow remote attackers to hijack the authentication of arbitrary users for reque…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1026

Published Jun 2, 2011

Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hijack the authentication of admi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1403

Published May 13, 2011

Cross-site request forgery (CSRF) vulnerability in the pieforms implementation in Mahara before 1.3.6 allows remote attackers to hijack the authentication of arbitrary users for r…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1325

Published May 13, 2011

Cross-site request forgery (CSRF) vulnerability in EC-CUBE before 2.11.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1545

Published May 3, 2011

Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.3 allows remote attackers to hijack the authentication of unspecified victims…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1543

Published Apr 29, 2011

Cross-site request forgery (CSRF) vulnerability in HP Systems Insight Manager (SIM) before 6.3 allows remote attackers to hijack the authentication of unspecified victims via unkn…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1685

Published Apr 22, 2011

Best Practical Solutions RT 3.8.0 through 3.8.9 and 4.0.0rc through 4.0.0rc7, when the CustomFieldValuesSources (aka external custom field) option is enabled, allows remote authen…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1721

Published Apr 19, 2011

Cross-site request forgery (CSRF) vulnerability in php/partie_administrateur/administration.php in WebJaxe 1.02 allows remote attackers to hijack the authentication of administrat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1682

Published Apr 13, 2011

Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0748

Published Apr 13, 2011

Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administrators for requests that (1) ad…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0746

Published Apr 13, 2011

Cross-site request forgery (CSRF) vulnerability in Forms/PortForwarding_Edit_1 on the ZyXEL O2 DSL Router Classic allows remote attackers to hijack the authentication of administr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0545

Published Mar 28, 2011

Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to hijack the authentication of adminis…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0440

Published Mar 28, 2011

Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to hijack the authentication of arbitrary users for req…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0059

Published Mar 2, 2011

Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authen…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4750

Published Mar 1, 2011

Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allows remote attackers to hijack the authentication of administ…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1104

Published Feb 28, 2011

Multiple cross-site request forgery (CSRF) vulnerabilities in Mutare EVM allow remote attackers to hijack the authentication of arbitrary users for requests that (1) change a PIN,…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0696

Published Feb 14, 2011

Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to co…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0447

Published Feb 14, 2011

Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0277

Published Feb 9, 2011

Cross-site request forgery (CSRF) vulnerability in HP Power Manager (HPPM) 4.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests th…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 9,126-9,150 of 9,473 CVEsPage 366 of 379