Lucene search

K
cveMitreCVE-2007-1520
HistoryMar 20, 2007 - 8:19 p.m.

CVE-2007-1520

2007-03-2020:19:00
CWE-352
mitre
web.nvd.nist.gov
29
cve-2007-1520
cross-site request forgery
csrf
php-nuke 8.0
security vulnerability

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

High

EPSS

0.025

Percentile

90.1%

The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows remote attackers to conduct CSRF attacks.

Affected configurations

Nvd
Node
phpnukephp-nukeRange8.0
OR
phpnukephp-nukeMatch5.6
OR
phpnukephp-nukeMatch6.5
OR
phpnukephp-nukeMatch7.0
OR
phpnukephp-nukeMatch7.1
OR
phpnukephp-nukeMatch7.2
OR
phpnukephp-nukeMatch7.3
OR
phpnukephp-nukeMatch7.4
OR
phpnukephp-nukeMatch7.5
OR
phpnukephp-nukeMatch7.6
OR
phpnukephp-nukeMatch7.7
OR
phpnukephp-nukeMatch7.8
OR
phpnukephp-nukeMatch7.9
VendorProductVersionCPE
phpnukephp-nuke*cpe:2.3:a:phpnuke:php-nuke:*:*:*:*:*:*:*:*
phpnukephp-nuke5.6cpe:2.3:a:phpnuke:php-nuke:5.6:*:*:*:*:*:*:*
phpnukephp-nuke6.5cpe:2.3:a:phpnuke:php-nuke:6.5:*:*:*:*:*:*:*
phpnukephp-nuke7.0cpe:2.3:a:phpnuke:php-nuke:7.0:*:*:*:*:*:*:*
phpnukephp-nuke7.1cpe:2.3:a:phpnuke:php-nuke:7.1:*:*:*:*:*:*:*
phpnukephp-nuke7.2cpe:2.3:a:phpnuke:php-nuke:7.2:*:*:*:*:*:*:*
phpnukephp-nuke7.3cpe:2.3:a:phpnuke:php-nuke:7.3:*:*:*:*:*:*:*
phpnukephp-nuke7.4cpe:2.3:a:phpnuke:php-nuke:7.4:*:*:*:*:*:*:*
phpnukephp-nuke7.5cpe:2.3:a:phpnuke:php-nuke:7.5:*:*:*:*:*:*:*
phpnukephp-nuke7.6cpe:2.3:a:phpnuke:php-nuke:7.6:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

High

EPSS

0.025

Percentile

90.1%

Related for CVE-2007-1520