CVE-2008-5400
10.12.2008, 06:44
Multiple cross-site request forgery (CSRF) vulnerabilities in mvnForum before 1.2.1 GA allow remote attackers to (1) create forums, (2) change account privileges, (3) enable accounts, or (4) disable accounts as a product administrator via unspecified vectors, possibly related to HTTP Referer headers.
Vendor | Product | Version |
---|---|---|
mvnforum | mvnforum | 𝑥 ≤ 1.2 |
mvnforum | mvnforum | 1.0.0:beta1 |
mvnforum | mvnforum | 1.0.0:beta2 |
mvnforum | mvnforum | 1.0.0:beta3 |
mvnforum | mvnforum | 1.0.0:rc1 |
mvnforum | mvnforum | 1.0.0:rc2 |
mvnforum | mvnforum | 1.0.0:rc3_01 |
mvnforum | mvnforum | 1.0.0:rc4 |
mvnforum | mvnforum | 1.0.0_beta1:_beta1 |
mvnforum | mvnforum | 1.0.0_beta2:_beta2 |
mvnforum | mvnforum | 1.0.0_beta3:_beta3 |
mvnforum | mvnforum | 1.0.0_rc1:_rc1 |
mvnforum | mvnforum | 1.0.0_rc2:_rc2 |
mvnforum | mvnforum | 1.0.0_rc3_01:_rc3_01 |
mvnforum | mvnforum | 1.0.0_rc4:_rc4 |
mvnforum | mvnforum | 1.0.0_rc4_04:_rc4_04 |
mvnforum | mvnforum | 1.0.2.:ga |
mvnforum | mvnforum | 1.0_ga:_ga |
mvnforum | mvnforum | 1.0_rc4:_rc4 |
mvnforum | mvnforum | 1.1:ga |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References