Lucene search

K
cveCertccCVE-2008-0182
HistoryFeb 05, 2008 - 12:00 a.m.

CVE-2008-0182

2008-02-0500:00:00
CWE-352
certcc
web.nvd.nist.gov
29
cve-2008-0182
cross-site request forgery
csrf vulnerability
liferay portal
authenticated users
shutdown message
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

55.9%

Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message.

Affected configurations

Nvd
Node
liferayliferay_enterprise_portalRange4.3.6
VendorProductVersionCPE
liferayliferay_enterprise_portal*cpe:2.3:a:liferay:liferay_enterprise_portal:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

55.9%

Related for CVE-2008-0182