CVE-2005-2059

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ubbcentral:ubb.threads:*:*:*:*:*:*:*:*

History

08 Feb 2024, 20:44

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=111963737202040&w=2 - () http://marc.info/?l=bugtraq&m=111963737202040&w=2 - Exploit, Mailing List
References () http://www.gulftech.org/?node=research&article_id=00084-06232005 - Exploit, Patch, Vendor Advisory () http://www.gulftech.org/?node=research&article_id=00084-06232005 - Broken Link, Exploit, Patch, Vendor Advisory
References () http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351 - Patch () http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351 - Broken Link, Patch
CPE cpe:2.3:a:ubbcentral:ubb.threads:6.4.2:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.5:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.3.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.2.3:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.3:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.2.2:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.0:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.4.4:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.4.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.2:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.4:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:6.4.3:*:*:*:*:*:*:*
cpe:2.3:a:ubbcentral:ubb.threads:*:*:*:*:*:*:*:*
CVSS v2 : 5.0
v3 : unknown
v2 : 5.0
v3 : 6.5
CWE NVD-CWE-Other CWE-352

Information

Published : 2005-06-29 04:00

Updated : 2024-02-08 20:44


NVD link : CVE-2005-2059

Mitre link : CVE-2005-2059

CVE.ORG link : CVE-2005-2059


JSON object : View

Products Affected

ubbcentral

  • ubb.threads
CWE
CWE-352

Cross-Site Request Forgery (CSRF)