Lucene search

K
cveMitreCVE-2008-3716
HistoryAug 19, 2008 - 7:41 p.m.

CVE-2008-3716

2008-08-1919:41:00
CWE-352
mitre
web.nvd.nist.gov
21
cve-2008-3716
cross-site request forgery
csrf vulnerability
harmoni
nvd
remote attackers
administrative modifications
security vulnerability

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

56.7%

Cross-site request forgery (CSRF) vulnerability in Harmoni before 1.6.0 allows remote attackers to make administrative modifications via a (1) save or (2) delete action to an unspecified component.

Affected configurations

Nvd
Node
harmoniharmoniRange1.4.7
OR
harmoniharmoniMatch0.0.2
OR
harmoniharmoniMatch0.0.3
OR
harmoniharmoniMatch0.0.4
OR
harmoniharmoniMatch0.0.5
OR
harmoniharmoniMatch0.1.0
OR
harmoniharmoniMatch0.2.0
OR
harmoniharmoniMatch0.3.0
OR
harmoniharmoniMatch0.3.1
OR
harmoniharmoniMatch0.3.2
OR
harmoniharmoniMatch0.5.1
OR
harmoniharmoniMatch0.6.0
OR
harmoniharmoniMatch0.6.2
OR
harmoniharmoniMatch0.7.0
OR
harmoniharmoniMatch0.7.1
OR
harmoniharmoniMatch0.7.2
OR
harmoniharmoniMatch0.7.6
OR
harmoniharmoniMatch0.7.7
OR
harmoniharmoniMatch0.9.0
OR
harmoniharmoniMatch0.10.1
OR
harmoniharmoniMatch0.11.0
OR
harmoniharmoniMatch0.12.0
OR
harmoniharmoniMatch0.12.1
OR
harmoniharmoniMatch0.12.3
OR
harmoniharmoniMatch0.13.0
OR
harmoniharmoniMatch0.13.1
OR
harmoniharmoniMatch0.13.2
OR
harmoniharmoniMatch0.13.3
OR
harmoniharmoniMatch0.13.4
OR
harmoniharmoniMatch0.13.5
OR
harmoniharmoniMatch0.13.6
OR
harmoniharmoniMatch0.13.7
OR
harmoniharmoniMatch1.0.0
OR
harmoniharmoniMatch1.0.1
OR
harmoniharmoniMatch1.0.2
OR
harmoniharmoniMatch1.0.3
OR
harmoniharmoniMatch1.0.5
OR
harmoniharmoniMatch1.0.6
OR
harmoniharmoniMatch1.1.0
OR
harmoniharmoniMatch1.3.0
OR
harmoniharmoniMatch1.3.2
OR
harmoniharmoniMatch1.3.4
OR
harmoniharmoniMatch1.3.5
OR
harmoniharmoniMatch1.4.2
OR
harmoniharmoniMatch1.4.6
VendorProductVersionCPE
harmoniharmoni*cpe:2.3:a:harmoni:harmoni:*:*:*:*:*:*:*:*
harmoniharmoni0.0.2cpe:2.3:a:harmoni:harmoni:0.0.2:*:*:*:*:*:*:*
harmoniharmoni0.0.3cpe:2.3:a:harmoni:harmoni:0.0.3:*:*:*:*:*:*:*
harmoniharmoni0.0.4cpe:2.3:a:harmoni:harmoni:0.0.4:*:*:*:*:*:*:*
harmoniharmoni0.0.5cpe:2.3:a:harmoni:harmoni:0.0.5:*:*:*:*:*:*:*
harmoniharmoni0.1.0cpe:2.3:a:harmoni:harmoni:0.1.0:*:*:*:*:*:*:*
harmoniharmoni0.2.0cpe:2.3:a:harmoni:harmoni:0.2.0:*:*:*:*:*:*:*
harmoniharmoni0.3.0cpe:2.3:a:harmoni:harmoni:0.3.0:*:*:*:*:*:*:*
harmoniharmoni0.3.1cpe:2.3:a:harmoni:harmoni:0.3.1:*:*:*:*:*:*:*
harmoniharmoni0.3.2cpe:2.3:a:harmoni:harmoni:0.3.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 451

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

56.7%

Related for CVE-2008-3716