Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Giudinvx

#19479of 53,624
13.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2012-3143
6.8
2012-02-21
Gazie · Gazie · CVE-2012-1220
**Name of the Vulnerable Software and Affected Versions** GAzie versions 5.20 and earlier **Description** A cross-site request forgery issue allows remote attackers to hijack the authentication of administrators for requests that change account information via an update action, such as changing the password. **Recommendations** For GAzie versions 5.20 and earlier, update to a version later than 5.20 to resolve the issue.
PT-2010-3658
6.8
2010-05-25
Gpeasy · Gpeasy Cms · CVE-2010-2039
**Name of the Vulnerable Software and Affected Versions** gpEasy CMS versions 1.6.2 and earlier **Description** A cross-site request forgery issue allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an Admin Users action to "index.php". **Recommendations** For gpEasy CMS versions 1.6.2 and earlier, as a temporary workaround, consider restricting access to the Admin Users action in "index.php" to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.