Логотип exploitDog
bind:CVE-2010-4729
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2010-4729

Количество 2

Количество 2

nvd логотип

CVE-2010-4729

около 15 лет назад

Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier for remote attackers to generate a flood of password requests and possibly conduct cross-site request forgery (CSRF) attacks via multiple form submissions.

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-j4jq-jwjr-wj8f

больше 3 лет назад

Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier for remote attackers to generate a flood of password requests and possibly conduct cross-site request forgery (CSRF) attacks via multiple form submissions.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2010-4729

Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier for remote attackers to generate a flood of password requests and possibly conduct cross-site request forgery (CSRF) attacks via multiple form submissions.

CVSS2: 6.8
0%
Низкий
около 15 лет назад
github логотип
GHSA-j4jq-jwjr-wj8f

Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier for remote attackers to generate a flood of password requests and possibly conduct cross-site request forgery (CSRF) attacks via multiple form submissions.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу