6.8
CVE-2010-4519
- EPSS 0.1%
- Veröffentlicht 23.12.2010 18:00:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Earl Miles ≫ Views Version5.x-1.0
Earl Miles ≫ Views Version5.x-1.1 Updatebeta
Earl Miles ≫ Views Version5.x-1.2 Updatebeta1
Earl Miles ≫ Views Version5.x-1.3 Updatebeta1
Earl Miles ≫ Views Version5.x-1.4 Updaterc1
Earl Miles ≫ Views Version5.x-1.4-2 Updaterc1
Earl Miles ≫ Views Version5.x-1.5
Earl Miles ≫ Views Version5.x-1.6
Earl Miles ≫ Views Version5.x-1.6 Updatebeta
Earl Miles ≫ Views Version5.x-1.6 Updatebeta2
Earl Miles ≫ Views Version5.x-1.6 Updatebeta3
Earl Miles ≫ Views Version5.x-1.6 Updatebeta4
Earl Miles ≫ Views Version5.x-1.6 Updatebeta5
Earl Miles ≫ Views Version5.x-1.7
Earl Miles ≫ Views Version5.x-1.x Updatedev
Earl Miles ≫ Views Version6.x-2.0
Earl Miles ≫ Views Version6.x-2.0 Updatealpha1
Earl Miles ≫ Views Version6.x-2.0 Updatealpha2
Earl Miles ≫ Views Version6.x-2.0 Updatealpha3
Earl Miles ≫ Views Version6.x-2.0 Updatealpha4
Earl Miles ≫ Views Version6.x-2.0 Updatealpha5
Earl Miles ≫ Views Version6.x-2.0 Updatebeta1
Earl Miles ≫ Views Version6.x-2.0 Updatebeta2
Earl Miles ≫ Views Version6.x-2.0 Updatebeta3
Earl Miles ≫ Views Version6.x-2.0 Updatebeta4
Earl Miles ≫ Views Version6.x-2.0 Updaterc1
Earl Miles ≫ Views Version6.x-2.0 Updaterc2
Earl Miles ≫ Views Version6.x-2.0 Updaterc3
Earl Miles ≫ Views Version6.x-2.0 Updaterc4
Earl Miles ≫ Views Version6.x-2.0 Updaterc5
Earl Miles ≫ Views Version6.x-2.1
Earl Miles ≫ Views Version6.x-2.2
Earl Miles ≫ Views Version6.x-2.3
Earl Miles ≫ Views Version6.x-2.4
Earl Miles ≫ Views Version6.x-2.5
Earl Miles ≫ Views Version6.x-2.6
Earl Miles ≫ Views Version6.x-2.7
Earl Miles ≫ Views Version6.x-2.8
Earl Miles ≫ Views Version6.x-2.9
Earl Miles ≫ Views Version6.x-2.10
Earl Miles ≫ Views Version6.x-2.x Updatedev
Earl Miles ≫ Views Version6.x-3.0 Updatealpha1
Earl Miles ≫ Views Version6.x-3.0 Updatealpha2
Earl Miles ≫ Views Version6.x-3.0 Updatealpha3
Earl Miles ≫ Views Version6.x-3.x Updatedev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.279 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.