Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-3262

Overview

Vulnerability Score 5.8 5.8
CVE Id CVE-2008-3262
Last Modified 19 Aug 2009 01:17:15
Published 22 Jul 2008 01:41:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-3262

Summary

Cross-site request forgery (CSRF) vulnerability in Claroline before 1.8.10 allows remote attackers to change passwords, related to lack of a requirement for the previous password.

Vulnerable Systems

Application

  • Claroline 1.2

  • Claroline 1.3

  • Claroline 1.4

  • Claroline 1.5

  • Claroline 1.5.3

  • Claroline 1.5.4

  • Claroline 1.6

  • Claroline 1.6 Beta

  • Claroline 1.6 Rc1

  • Claroline 1.7

  • Claroline 1.7.1

  • Claroline 1.7.2

  • Claroline 1.7.3

  • Claroline 1.7.4

  • Claroline 1.7.5

  • Claroline 1.7.6

  • Claroline 1.7.7

  • Claroline 1.8.0

  • Claroline 1.8.1

  • Claroline 1.8.2

  • Claroline 1.8.3

  • Claroline 1.8.4

  • Claroline 1.8.5

  • Claroline 1.8.6

  • Claroline 1.8.7

  • Claroline 1.8.8

  • Claroline 1.8.9


References

XF - claroline-unspecified-csrf(43974)

XF - claroline-unknown-unspecified(43854)

BUGTRAQ - 20080718 [DSECRG-08-030] Claroline 1.8.9 Multiple Security Vulnerabilities

CONFIRM - http://wiki.claroline.net/index.php/Changelog_1.8.x#Modification_between_claroline_1.8.9_and_1.8.10

CONFIRM - http://sourceforge.net/project/shownotes.php?release_id=613634

SREASON - 4020

SECUNIA - 31116


Last Updated: 27 May 2016 10:48:08