CVE-2011-1482

Multiple cross-site request forgery (CSRF) vulnerabilities in mainfile.php in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts or (2) grant the administrative privilege to a user account, related to a Referer check that uses a substring comparison.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
VendorProductVersion
phpnukephp-nuke
𝑥
≤ 8.0
phpnukephp-nuke
5.0
phpnukephp-nuke
5.0.1
phpnukephp-nuke
5.1
phpnukephp-nuke
5.2
phpnukephp-nuke
5.3
phpnukephp-nuke
5.3.1
phpnukephp-nuke
5.4
phpnukephp-nuke
5.5
phpnukephp-nuke
5.6
phpnukephp-nuke
6.0
phpnukephp-nuke
6.5
phpnukephp-nuke
6.6
phpnukephp-nuke
6.7
phpnukephp-nuke
6.8
phpnukephp-nuke
6.9
phpnukephp-nuke
7.0
phpnukephp-nuke
7.1
phpnukephp-nuke
7.2
phpnukephp-nuke
7.3
phpnukephp-nuke
7.4
phpnukephp-nuke
7.5
phpnukephp-nuke
7.6
phpnukephp-nuke
7.7
phpnukephp-nuke
7.8
phpnukephp-nuke
7.9
𝑥
= Vulnerable software versions