CVE-2008-6729

Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that modify an account via the (1) password or (2) email_address parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:phpmotion:phpmotion:*:*:*:*:*:*:*:*
cpe:2.3:a:phpmotion:phpmotion:1.0:*:*:*:*:*:*:*
cpe:2.3:a:phpmotion:phpmotion:2.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:57

Type Values Removed Values Added
References () http://osvdb.org/50999 - () http://osvdb.org/50999 -
References () http://secunia.com/advisories/33309 - Vendor Advisory () http://secunia.com/advisories/33309 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/47585 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/47585 -
References () https://www.exploit-db.com/exploits/7557 - () https://www.exploit-db.com/exploits/7557 -

Information

Published : 2009-04-20 14:30

Updated : 2024-11-21 00:57


NVD link : CVE-2008-6729

Mitre link : CVE-2008-6729

CVE.ORG link : CVE-2008-6729


JSON object : View

Products Affected

phpmotion

  • phpmotion
CWE
CWE-352

Cross-Site Request Forgery (CSRF)