Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=111963737202040&w=2 | Exploit Mailing List |
http://www.gulftech.org/?node=research&article_id=00084-06232005 | Broken Link Exploit Patch Vendor Advisory |
http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351 | Broken Link Patch |
http://marc.info/?l=bugtraq&m=111963737202040&w=2 | Exploit Mailing List |
http://www.gulftech.org/?node=research&article_id=00084-06232005 | Broken Link Exploit Patch Vendor Advisory |
http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351 | Broken Link Patch |
Configurations
History
20 Nov 2024, 23:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=111963737202040&w=2 - Exploit, Mailing List | |
References | () http://www.gulftech.org/?node=research&article_id=00084-06232005 - Broken Link, Exploit, Patch, Vendor Advisory | |
References | () http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351 - Broken Link, Patch |
08 Feb 2024, 20:44
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 6.5 |
CWE | CWE-352 | |
CPE | cpe:2.3:a:ubbcentral:ubb.threads:6.3.1:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.1:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.0:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.2:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.0.2:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.4.3:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.0.3:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.2.1:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.4:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.0.1:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.5.1:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.3:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.5.1.1:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.4.4:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.2.3:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.5:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.1.1:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.2.2:*:*:*:*:*:*:* cpe:2.3:a:ubbcentral:ubb.threads:6.4.1:*:*:*:*:*:*:* |
cpe:2.3:a:ubbcentral:ubb.threads:*:*:*:*:*:*:*:* |
References | (MISC) http://www.gulftech.org/?node=research&article_id=00084-06232005 - Broken Link, Exploit, Patch, Vendor Advisory | |
References | (BUGTRAQ) http://marc.info/?l=bugtraq&m=111963737202040&w=2 - Exploit, Mailing List | |
References | (MISC) http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351 - Broken Link, Patch |
Information
Published : 2005-06-29 04:00
Updated : 2024-11-20 23:58
NVD link : CVE-2005-2059
Mitre link : CVE-2005-2059
CVE.ORG link : CVE-2005-2059
JSON object : View
Products Affected
ubbcentral
- ubb.threads
CWE
CWE-352
Cross-Site Request Forgery (CSRF)