6
CVE-2008-6331
- EPSS 0.12%
- Veröffentlicht 27.02.2009 16:30:08
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site request forgery (CSRF) vulnerabilities in Streber before 0.08093 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Streber-pm ≫ Streber Version <= 0.0803
Streber-pm ≫ Streber Version0.08
Streber-pm ≫ Streber Version0.054
Streber-pm ≫ Streber Version0.055
Streber-pm ≫ Streber Version0.056
Streber-pm ≫ Streber Version0.078
Streber-pm ≫ Streber Version0.079
Streber-pm ≫ Streber Version0.0791
Streber-pm ≫ Streber Version0.0792
Streber-pm ≫ Streber Version0.0794
Streber-pm ≫ Streber Version0.0795
Streber-pm ≫ Streber Version0.0796
Streber-pm ≫ Streber Version0.0801
Streber-pm ≫ Streber Version0.07991
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.28 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.