映射到 CWE-352 的搜索结果 (1407)

CVE-2016-0348(发布:2018-02-21 11:29:00)NM
CVSS6.0

[原文]Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111813.

CVE-2018-6941(发布:2018-02-20 10:29:00)NM
CVSS6.8

[原文]A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with XSS.

CVE-2018-7219(发布:2018-02-19 09:29:00)NM
CVSS6.8

[原文]application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/index.php/admin/admin/edit.html request.

CVE-2018-7216(发布:2018-02-18 01:29:00)NM
CVSS6.0

[原文]Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal allows remote authenticated users to hijack the authentication of application users for requests that modify their personal data by leveraging lack of anti-CSRF tokens.

CVE-2018-7176(发布:2018-02-15 23:29:00)NM
CVSS6.8

[原文]FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page).

CVE-2017-5796(发布:2018-02-15 17:29:05)NMPS
CVSS9.3

[原文]A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found.

首页上一页678910111213下一页尾页 第8页 / 共235页

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站