Total
6080 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-17908 | 1 Responsive Realestate Script Project | 1 Responsive Realestate Script | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general. | |||||
CVE-2017-17905 | 1 Car Rental Script Project | 1 Car Rental Script | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php. | |||||
CVE-2017-17903 | 1 Fortunescripts | 1 Lynda Clone | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel. | |||||
CVE-2017-17894 | 1 Basic Job Site Script Project | 1 Basic Job Site Script | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Readymade Job Site Script has CSRF via the /job URI. | |||||
CVE-2017-17891 | 1 Readymade Video Sharing Script Project | 1 Readymade Video Sharing Script | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Readymade Video Sharing Script has CSRF via user-profile-edit.php. | |||||
CVE-2017-17835 | 1 Apache | 1 Airflow | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow. | |||||
CVE-2017-17830 | 1 Doditsolutions | 1 Bus Booking Script | 2024-11-21 | 6.0 MEDIUM | 6.8 MEDIUM |
Bus Booking Script has CSRF via admin/new_master.php. | |||||
CVE-2017-17827 | 1 Piwigo | 1 Piwigo | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration§ion=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions. | |||||
CVE-2017-17774 | 1 Piwigo | 1 Piwigo | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
admin/configuration.php in Piwigo 2.9.2 has CSRF. | |||||
CVE-2017-17552 | 1 Zohocorp | 1 Manageengine Admanager Plus | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted. | |||||
CVE-2017-17550 | 1 Zyxel | 2 Zywall Usg 100, Zywall Usg 100 Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS. | |||||
CVE-2017-17056 | 1 Zkteco | 1 Zktime Web | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function of the Modify Password component, reachable via the old_password, new_password1, and new_password2 parameters to the /accounts/password_change/ URI. An attacker takes advantage of this scenario and creates a crafted CSRF link to add himself as an administrator to the ZKTime Web Software. He then uses social engineering methods to trick the administrator into clicking the forged HTTP request. The request is executed and the attacker becomes the Administrator of the ZKTime Web Software. If the vulnerability is successfully exploited, then an attacker (who would be a normal user of the web application) can escalate his privileges and become the administrator of ZKTime Web Software. | |||||
CVE-2017-16886 | 1 Fiberhome | 2 Lm53q1, Lm53q1 Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal. | |||||
CVE-2017-16862 | 1 Atlassian | 1 Jira | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability. | |||||
CVE-2017-16780 | 1 Mybb | 1 Mybb | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file. | |||||
CVE-2017-16756 | 1 Userscape | 1 Helpspot | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=password.change" endpoint. This allows an attacker to change the password of another user's HelpSpot account. | |||||
CVE-2017-16570 | 1 Keystonejs | 1 Keystone | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In other words, it fails to reject requests that lack an x-csrf-token header. | |||||
CVE-2017-16565 | 1 Grandstream | 2 Ht802, Ht802 Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the default password of 123 and submit arbitrary requests. | |||||
CVE-2017-16563 | 1 Grandstream | 2 Ht802, Ht802 Firmware | 2024-11-21 | 6.0 MEDIUM | 8.0 HIGH |
Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to cgi-bin/update. | |||||
CVE-2017-16244 | 1 Octobercms | 1 October | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack bypasses a protection mechanism involving X-CSRF headers and CSRF tokens via a certain _handler postback variable. |