Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,451 CVEs tagged with CWE-352143 Critical, 3,385 High, 5,730 Medium, 184 Low, 9 Unrated.

CVE-2010-3883

Published Oct 8, 2010

Cross-site request forgery (CSRF) vulnerability in the Change Group Permissions module in CMS Made Simple 1.7.1 and earlier allows remote attackers to hijack the authentication of…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3603

Published Sep 24, 2010

Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to hijack the aut…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1767

Published Sep 24, 2010

Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows rem…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3464

Published Sep 17, 2010

Cross-site request forgery (CSRF) vulnerability in admin/manager_users.class.php in SantaFox 2.02, and possibly earlier, allows remote attackers to hijack the authentication of ad…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3213

Published Sep 7, 2010

Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4898

Published Sep 7, 2010

Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary users for requests that update pages, as de…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4981

Published Aug 25, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in Photokorn Gallery 1.81 allow remote attackers to hijack the authentication of administrators.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2234

Published Aug 19, 2010

Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators for direct requests t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3030

Published Aug 17, 2010

Cross-site request forgery (CSRF) vulnerability in Tomaz Muraus Open Blog 1.2.1, and possibly earlier, allows remote attackers to hijack the authentication of administrators for r…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3026

Published Aug 16, 2010

Cross-site request forgery (CSRF) vulnerability in application/modules/admin/controllers/users.php in Tomaz Muraus Open Blog 1.2.1, and possibly earlier, allows remote attackers t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3024

Published Aug 16, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in user/main/update_user in DiamondList 0.1.6, and possibly earlier, allow remote attackers to hijack the authentication…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4942

Published Jul 22, 2010

Cross-site request forgery (CSRF) vulnerability in ACollab 1.2 allows remote attackers to hijack the authentication of arbitrary users for requests that add personal agenda items.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1668

Published Jul 6, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers to hijack the authentication…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2594

Published Jul 2, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in InterSect Alliance Snare Agent 3.2.3 and earlier on Solaris, Snare Agent 3.1.7 and ea…

CVSS 6.8 · Medium

CVE-2010-2231

Published Jun 28, 2010

Cross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to hijack t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4907

Published Jun 25, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in oBlog allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin pa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4906

Published Jun 25, 2010

Cross-site request forgery (CSRF) vulnerability in index.php in Acc PHP eMail 1.1 allows remote attackers to hijack the authentication of administrators for requests that change p…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4905

Published Jun 25, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Acc Statistics 1.1 allow remote attackers to hijack the authentication of administrators for requests th…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2345

Published Jun 21, 2010

Cross-site request forgery (CSRF) vulnerability in odCMS 1.06, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests that chang…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0540

Published Jun 17, 2010

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allo…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2282

Published Jun 15, 2010

Cross-site request forgery (CSRF) vulnerability in TomatoCMS 2.0.6 allows remote attackers to hijack the authentication of administrators for requests that change the administrati…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 9,151-9,175 of 9,451 CVEsPage 367 of 379