Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,429 CVEs tagged with CWE-352140 Critical, 3,377 High, 5,723 Medium, 183 Low, 6 Unrated.

CVE-2010-1150

Published Apr 20, 2010

MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authentica…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4773

Published Apr 20, 2010

Cross-site request forgery (CSRF) vulnerability in the order-management functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal allows remote att…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0992

Published Apr 9, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in Pulse CMS Basic 1.2.2 and 1.2.3, and possibly Pulse Pro before 1.3.2, allow remote attackers to hijack the authentica…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1244

Published Apr 5, 2010

Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified vic…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0921

Published Mar 3, 2010

Cross-site request forgery (CSRF) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to hijack the authen…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0713

Published Feb 26, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authentication of an administrator…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0711

Published Feb 25, 2010

Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to hijack the authentica…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0709

Published Feb 25, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authentication of users or administrators for requests that change…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0638

Published Feb 15, 2010

Cross-site request forgery (CSRF) vulnerability in WebCalendar 1.2.0 allows remote attackers to hijack the authentication of administrators for requests that change the administra…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0289

Published Feb 15, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remote attackers to hijack the aut…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0637

Published Feb 12, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to hijack the authentication of administra…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4572

Published Jan 5, 2010

Cross-site request forgery (CSRF) vulnerability in PhpShop 0.8.1 allows remote attackers to hijack the authentication of arbitrary users for requests that invoke the cartAdd funct…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4555

Published Jan 4, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in AgoraCart 5.2.005 and 5.2.006 and AgoraCart GOLD 5.5.005 allow remote attackers to hijack the authentication of admin…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4517

Published Dec 31, 2009

Cross-site request forgery (CSRF) vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to hijack the authentication of arbi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4407

Published Dec 23, 2009

Multiple cross-site request forgery (CSRF) vulnerabilities in PyForum 1.0.3 and possibly earlier versions, and possibly zForum, allow remote attackers to hijack the authentication…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3580

Published Dec 23, 2009

Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitrary users for requests that change a pa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4385

Published Dec 22, 2009

Multiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to (1) hijack the authentication of arbitrary users for req…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4365

Published Dec 21, 2009

Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the authentication of administrators for requests…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4349

Published Dec 17, 2009

Cross-site request forgery (CSRF) vulnerability in administration/administrators.php in Link Up Gold 5.0 allows remote attackers to hijack the authentication of administrators for…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4297

Published Dec 16, 2009

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified vict…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4173

Published Dec 2, 2009

Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to hijack the authentication of administrators for r…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4120

Published Dec 1, 2009

Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authentication of the administrator for requests that (1) delete…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 9,176-9,200 of 9,429 CVEsPage 368 of 378