CVE-2011-1482
Multiple cross-site request forgery (CSRF) vulnerabilities in mainfile.php in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts or (2) grant the…
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in mainfile.php in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts or (2) grant the administrative privilege to a user account, related to a Referer check that uses a substring comparison.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- phpnuke/php-nuke
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2011/03/23/9Exploit
- http://www.openwall.com/lists/oss-security/2011/03/30/8Exploit
- http://yehg.net/lab/pr0js/advisories/%5Bphpnuke-8.x%5D_cross_site_request_forgery
- http://www.openwall.com/lists/oss-security/2011/03/23/9Exploit
- http://www.openwall.com/lists/oss-security/2011/03/30/8Exploit
- http://yehg.net/lab/pr0js/advisories/%5Bphpnuke-8.x%5D_cross_site_request_forgery
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.