Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
csrf vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2013-4722
Multiple cross-site scripting (XSS) vulnerabilities in Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allow remote malicious users to inject arbitrary web script or HTML via the (1) username, (2) u...
Ddsn Cm3 Acora Content Management System 6.0.2/1a
Ddsn Cm3 Acora Content Management System 5.5.7/12b
Ddsn Cm3 Acora Content Management System 5.5.0/1b-p1
Ddsn Cm3 Acora Content Management System 6.0.6/1a
516
VMScore
CVE-2013-4723
Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the l parameter to track.aspx.
Ddsn Cm3 Acora Content Management System 6.0.2/1a
Ddsn Cm3 Acora Content Management System 5.5.7/12b
Ddsn Cm3 Acora Content Management System 5.5.0/1b-p1
Ddsn Cm3 Acora Content Management System 6.0.6/1a
445
VMScore
CVE-2013-4724
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote malicious users to obtain potentially sensitive informatio...
Ddsn Cm3 Acora Content Management System 6.0.2/1a
Ddsn Cm3 Acora Content Management System 5.5.7/12b
Ddsn Cm3 Acora Content Management System 5.5.0/1b-p1
Ddsn Cm3 Acora Content Management System 6.0.6/1a
445
VMScore
CVE-2013-4725
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote malicious users to capture this cookie by intercepting its transmis...
Ddsn Cm3 Acora Content Management System 6.0.2/1a
Ddsn Cm3 Acora Content Management System 5.5.7/12b
Ddsn Cm3 Acora Content Management System 5.5.0/1b-p1
Ddsn Cm3 Acora Content Management System 6.0.6/1a
445
VMScore
CVE-2013-4728
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote malicious users to obtain sensitive information via a .. (dot dot) in the "l" parameter, which reveals the installation path in an error message.
Ddsn Cm3 Acora Content Management System 6.0.2/1a
Ddsn Cm3 Acora Content Management System 5.5.7/12b
Ddsn Cm3 Acora Content Management System 5.5.0/1b-p1
Ddsn Cm3 Acora Content Management System 6.0.6/1a
605
VMScore
CVE-2013-4726
Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote malicious users to hijack the authentication of unspecified victims via unknown vectors.
Ddsn Cm3 Acora Content Management System 6.0.2/1a
Ddsn Cm3 Acora Content Management System 5.5.7/12b
Ddsn Cm3 Acora Content Management System 5.5.0/1b-p1
Ddsn Cm3 Acora Content Management System 6.0.6/1a
605
VMScore
CVE-2014-5361
Multiple cross-site request forgery (CSRF) vulnerabilities in Landesk Management Suite 9.6 and previous versions allow remote malicious users to hijack the authentication of administrators for requests that (1) start, (2) stop, or (3) restart services via a request to remote/serv...
Landesk Landesk Management Suite
578
VMScore
CVE-2014-5362
The admin interface in Landesk Management Suite 9.6 and previous versions allows remote malicious users to conduct remote file inclusion attacks involving ASPX pages from third-party sites via the d parameter to (1) ldms/sm_actionfrm.asp or (2) remote/frm_coremainfrm.aspx; or the...
Landesk Landesk Management Suite
605
VMScore
CVE-2019-15150
In the OAuth2 Client extension prior to 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function.
Schine.games Mw-oauth2client
668
VMScore
CVE-2015-7924
eWON devices with firmware prior to 10.1s0 do not trigger the discarding of browser session data in response to a log-off action, which makes it easier for remote malicious users to obtain access by leveraging an unattended workstation.
Ewon Ewon Firmware
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »