CVE-2009-1455

Multiple cross-site request forgery (CSRF) vulnerabilities in WebCollab before 2.50 (aka Billy Goat) allow remote attackers to hijack the authentication of administrators for requests that change an arbitrary password or have other unspecified impact.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:andrew_simpson:webcollab:2.20:*:*:*:*:*:*:*
cpe:2.3:a:andrew_simpson:webcollab:2.30:*:*:*:*:*:*:*
cpe:2.3:a:andrew_simpson:webcollab:2.31:*:*:*:*:*:*:*
cpe:2.3:a:andrew_simpson:webcollab:2.40:*:*:*:*:*:*:*

History

21 Nov 2024, 01:02

Type Values Removed Values Added
References () http://holisticinfosec.org/content/view/108/45/ - Patch () http://holisticinfosec.org/content/view/108/45/ - Patch
References () http://secunia.com/advisories/34568 - Vendor Advisory () http://secunia.com/advisories/34568 - Vendor Advisory
References () http://sourceforge.net/project/shownotes.php?release_id=676245&group_id=75945 - Patch () http://sourceforge.net/project/shownotes.php?release_id=676245&group_id=75945 - Patch
References () http://www.osvdb.org/53781 - () http://www.osvdb.org/53781 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/49940 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/49940 -

Information

Published : 2009-04-28 16:30

Updated : 2024-11-21 01:02


NVD link : CVE-2009-1455

Mitre link : CVE-2009-1455

CVE.ORG link : CVE-2009-1455


JSON object : View

Products Affected

andrew_simpson

  • webcollab
CWE
CWE-352

Cross-Site Request Forgery (CSRF)