Vulnerabilities > CVE-2005-2411 - Unspecified vulnerability in Tdiary 2.1.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN tdiary
nessus
Summary
Cross-Site Request Forgery (CSRF) vulnerability in tDiary 2.1.1, and tDiary 2.0.1 and earlier, allows remote attackers to conduct actions as another user, and execute commands on the server, via a URL that is activated by the user.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-808.NASL |
description | Yutaka Oiwa and Hiromitsu Takagi discovered a Cross-Site Request Forgery (CSRF) vulnerability in tdiary, a new generation weblog that can be exploited by remote attackers to alter the users information. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19683 |
published | 2005-09-13 |
reporter | This script is Copyright (C) 2005-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/19683 |
title | Debian DSA-808-1 : tdiary - design error |
code |
|
References
- http://secunia.com/advisories/16329
- http://secunia.com/advisories/16329
- http://secunia.com/advisories/16787
- http://secunia.com/advisories/16787
- http://sourceforge.net/forum/forum.php?forum_id=482743
- http://sourceforge.net/forum/forum.php?forum_id=482743
- http://www.debian.org/security/2005/dsa-808
- http://www.debian.org/security/2005/dsa-808
- http://www.osvdb.org/18604
- http://www.osvdb.org/18604
- http://www.securityfocus.com/bid/14500
- http://www.securityfocus.com/bid/14500
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21735
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21735