Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-4898

Опубликовано: 07 сент. 2010
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL for a save script in the ACTION attribute of a FORM element, in conjunction with a call to the submit method in the onload attribute of a BODY element. NOTE: this issue exists because of an insufficient fix for CVE-2009-1339.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

hardy

ignored

end of life
jaunty

ignored

end of life
karmic

ignored

end of life
lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

upstream

released

4.3.2

Показывать по

Ссылки на источники

EPSS

Процентиль: 33%
0.00126
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

nvd
больше 15 лет назад

Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL for a save script in the ACTION attribute of a FORM element, in conjunction with a call to the submit method in the onload attribute of a BODY element. NOTE: this issue exists because of an insufficient fix for CVE-2009-1339.

github
больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL for a save script in the ACTION attribute of a FORM element, in conjunction with a call to the submit method in the onload attribute of a BODY element. NOTE: this issue exists because of an insufficient fix for CVE-2009-1339.

EPSS

Процентиль: 33%
0.00126
Низкий

6.8 Medium

CVSS2