CVE-2011-1954
06.06.2011, 19:55
Multiple cross-site request forgery (CSRF) vulnerabilities in Post Revolution 0.8.0c-2 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests to (1) ajax-weblog-guardar.php, (2) verpost.php, (3) comments.php, or (4) perfil.php.
Vendor | Product | Version |
---|---|---|
postrev | post_revolution | 𝑥 ≤ 0.8.0c-2 |
postrev | post_revolution | 0.6.2:beta |
postrev | post_revolution | 0.6.3:beta |
postrev | post_revolution | 0.6.4 |
postrev | post_revolution | 0.6.5 |
postrev | post_revolution | 0.6.6 |
postrev | post_revolution | 0.7.0:rc1 |
postrev | post_revolution | 0.7.0:rc2 |
postrev | post_revolution | 0.7.0:rc3 |
postrev | post_revolution | 0.7.0:rc4 |
postrev | post_revolution | 0.8.0:alpha |
postrev | post_revolution | 0.8.0b:b |
postrev | post_revolution | 0.8.0c:c |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References