Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-0709

Опубликовано: 25 фев. 2010
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authentication of users or administrators for requests that change the email address or password via the user action to index.php, and (2) hijack the authentication of the administrator for requests that create a new user via the admin/modules/user/new action to limny/index.php.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:limny:limny:2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03164
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

github
почти 4 года назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authentication of users or administrators for requests that change the email address or password via the user action to index.php, and (2) hijack the authentication of the administrator for requests that create a new user via the admin/modules/user/new action to limny/index.php.

EPSS

Процентиль: 87%
0.03164
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-352