Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2017-03-17 CVE-2017-3877 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Unified Communications Manager 11.5(1.11.007.2)
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software.
network
low complexity
cisco CWE-352
6.5
2017-03-17 CVE-2017-0045 Cross-Site Request Forgery (CSRF) vulnerability in Microsoft Windows 7, Windows Server 2008 and Windows Vista
Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site Request Forgery Vulnerability."
local
low complexity
microsoft CWE-352
5.5
2017-03-16 CVE-2017-6379 Cross-Site Request Forgery (CSRF) vulnerability in Drupal
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF.
network
high complexity
drupal CWE-352
7.5
2017-03-15 CVE-2017-6918 Cross-Site Request Forgery (CSRF) vulnerability in Bigtreecms Bigtree CMS 4.2.16
CSRF exists in BigTree CMS 4.2.16 with the value[#][*] parameter to the admin/settings/update/ page.
network
low complexity
bigtreecms CWE-352
4.3
2017-03-15 CVE-2017-6917 Cross-Site Request Forgery (CSRF) vulnerability in Bigtreecms Bigtree CMS 4.2.16
CSRF exists in BigTree CMS 4.2.16 with the value parameter to the admin/settings/update/ page.
network
low complexity
bigtreecms CWE-352
4.3
2017-03-15 CVE-2017-6916 Cross-Site Request Forgery (CSRF) vulnerability in Bigtreecms Bigtree CMS 4.1.8
CSRF exists in BigTree CMS 4.1.18 with the nav-social[#] parameter to the admin/settings/update/ page.
network
low complexity
bigtreecms CWE-352
4.3
2017-03-15 CVE-2017-6915 Cross-Site Request Forgery (CSRF) vulnerability in Bigtreecms Bigtree CMS 4.1.8
CSRF exists in BigTree CMS 4.1.18 with the colophon parameter to the admin/settings/update/ page.
network
low complexity
bigtreecms CWE-352
4.3
2017-03-15 CVE-2017-6914 Cross-Site Request Forgery (CSRF) vulnerability in Bigtreecms Bigtree CMS 4.1.8/4.2.16
CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page.
network
low complexity
bigtreecms CWE-352
7.1
2017-03-15 CVE-2017-6366 Cross-Site Request Forgery (CSRF) vulnerability in Netgear Dgn2200 Firmware
Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that perform DNS lookups via the host_name parameter to dnslookup.cgi.
network
low complexity
netgear CWE-352
8.8
2017-03-14 CVE-2016-8018 Cross-Site Request Forgery (CSRF) vulnerability in Mcafee Virusscan Enterprise
Cross-site request forgery (CSRF) vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to execute unauthorized commands via a crafted user input.
network
low complexity
mcafee CWE-352
4.3