CVE-2008-0788
15.02.2008, 01:00
Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and earlier allow remote attackers to (1) hijack the authentication of moderators or administrators for requests that delete threads via a do_multideletethreads action to moderation.php and (2) hijack the authentication of arbitrary users for requests that delete private messages (PM) via a delete action to private.php.
Vendor | Product | Version |
---|---|---|
mybb | mybb | 𝑥 ≤ 1.2.11 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References