Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-5828

Опубликовано: 05 нояб. 2007
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 6.8

Описание

** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module.

РелизСтатусПримечание
dapper

DNE

devel

ignored

edgy

DNE

feisty

ignored

end of life, was needs-triage
gutsy

ignored

end of life, was needs-triage
hardy

ignored

intrepid

ignored

jaunty

ignored

karmic

ignored

upstream

ignored

Показывать по

Ссылки на источники

EPSS

Процентиль: 42%
0.00196
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

redhat
почти 18 лет назад

Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module

nvd
больше 17 лет назад

Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module

debian
больше 17 лет назад

Cross-site request forgery (CSRF) vulnerability in the admin panel in ...

github
больше 3 лет назад

** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module.

EPSS

Процентиль: 42%
0.00196
Низкий

6.8 Medium

CVSS2