CVE-2007-1638
Published Mar 23, 2007
Last updated 6 years ago
Overview
- Description
- Multiple cross-site request forgery (CSRF) vulnerabilities in the check_csrftoken function in lib/lib.inc.php in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote attackers to perform unauthorized actions as an arbitrary user via the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Notes, (5) Search, (6) Mail, or (7) Filemanager module; the (9) summary page; or unspecified other files.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Evaluator
- Comment
- -
- Impact
- Successful exploitation requires that variable "magic_quotes_gpc" is disabled.
- Solution
- Successful exploitation requires that variable "magic_quotes_gpc" is disabled.
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:phpprojekt:phpprojekt:5.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "12ABC36B-7E7E-4B99-8639-45339F6A280D" } ], "operator": "OR" } ] } ]