CVE-2011-1682
Published Apr 13, 2011
Last updated 7 years ago
Overview
- Description
- Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-352
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:tincan:phplist:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2462189-0CD0-4B40-A7DE-7CD29B6C5FB9", "versionEndIncluding": "2.10.13" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5FC454AF-1B16-4448-9F5A-80D656F9551B" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2F08591B-A066-40F4-97A4-F7EF1FE40FF1" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.1.2b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "994CBD86-E713-458E-AD7B-5357BD747319" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.1.3b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0394F819-8734-4418-A5D9-081B0ABED9AB" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.1.4b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "42F1E692-B80F-4F45-A694-F620B928F2DA" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "53EF60DE-FA1D-4F0E-80D8-EE87041741C9" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.1.5b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DC9F1619-4300-4674-AB7F-3B6C182C1A1D" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B923032-FB9C-42EB-AAF3-0AFC40690121" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5CEA44B-B45D-46E6-9740-7AFCAD676C33" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F0B52E71-CB78-438F-913B-3B49BA135F52" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.3.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46BE05C7-CFB0-48E8-999B-5B4B39D0E16F" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "648BE81A-7987-491C-8ED6-E737D83D3D50" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE9D9D96-AB9E-4938-80AD-4F012894067F" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE7F2489-59E1-4676-A46B-FC94DBA011D9" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "09EDB2B3-985E-4B26-95E8-5B179810AB30" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AFCDC95D-E5CC-4A62-B0CA-85252F880005" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B80875CA-261C-4B66-8A8B-5007CD645230" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "93584A2D-F093-4691-9A56-0B7CF9B82D27" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1AF7994C-A3BF-4846-A598-69E5FAA410E1" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D20C18F5-0D20-488E-A685-95537825F631" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2DAFAD62-46AE-4C2B-8338-9F01468C4D5B" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "571DA919-BEA6-4033-B1A6-5B0305281135" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7825E3FF-BD5C-466B-9D68-ABC269229DC7" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.9.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "84DF3E96-8035-4290-9B29-5C3795A04852" }, { "criteria": "cpe:2.3:a:tincan:phplist:1.9.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CBE1716C-536C-426C-BF26-55CBEC445485" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A661DEE-0AF7-4CA1-9BDD-A8E3C34D293D" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B2D6C9F-9700-4C81-B3D5-0FCAC1E6CA09" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22D86B15-1F3A-4EFA-8D7F-7ECD8F26C2ED" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE1CA9D6-E9C5-4C61-AB58-850A785C58EA" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E5B5358C-53BA-4A63-8EB4-72F86B67F023" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "154AECE5-DC59-49B9-A756-36B0049A0C78" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0755ABE4-C9A4-477F-AC0C-03655F4A2505" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FC17BA8-6FEA-40B2-8734-9DD873E6FC1E" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F8D1B20B-7120-4F12-AA3F-775952F9F315" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8434A23C-F4EB-4F3B-BE55-BBC599E3FC67" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A63F9ADB-90D7-49E3-ABDF-C75B218486C7" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "42CDBD10-EE7A-4185-BCCB-85AB0D9BDD47" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.4.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F52B116-6306-4620-B3DE-C77129DEBC75" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CA9A72F-C975-4CAC-B63B-BD74CCF97640" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B355BF6-DDAB-4643-8480-9B850418121D" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA8F9F34-7F4B-4B08-80A0-7495AE30F8F9" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23D04A86-5992-469E-BECB-341BB659EB10" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55656478-6680-4FD2-B322-0C73DD2380BF" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34F3DD54-BCEC-433B-9434-2129A967B234" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.5.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3ABABD5C-624A-4ABC-9265-C2BBC6435BCC" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.5.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2381905B-8532-4E67-ADAB-78321D153AED" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.5.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD67705B-7589-4E4E-85BF-1C1EC7001052" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CBE10CFB-A604-4C6E-ACE6-FD441C47D296" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F1EC7F51-B790-4333-9A2F-44693B3A7E8E" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "784C97D4-740E-4C65-98ED-FA03EC3EFAA8" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F94101A7-419E-4ACF-AB75-F0B0DA6E7021" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D6F52B3C-7925-4970-AA84-732B34DD2FF0" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5140DBAC-6AF0-41D0-972C-4F97BA06F488" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.6.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CC2A6FB5-0CE1-4952-9763-7AA0E605A7C9" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "665AC8D2-D3E6-470C-800B-0FD5AACE77BB" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA2FFBB2-E4C0-4F16-90D6-9D3FB2105C35" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "15C06CBF-3F4B-4D10-9FF4-21985354ED3A" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.8.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "018BA2DC-D1F7-4995-9D72-C38A2B087F8D" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.8.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "516EB08E-F724-4638-8174-1FB527CE8E5F" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.9.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C4B0EA29-302E-4FFB-88E2-5A4CDF195BA6" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.9.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "048787BE-1E97-40B1-94F3-ADA674207396" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.9.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2DB56F18-A63B-4557-AB5E-E83BFEDED0F5" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.10.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5BAFF48D-67A7-40DA-9762-DB416E1442C1" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.10.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86D12DE2-9CCA-4670-B119-8BF02A48453D" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.10.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A56C8952-210A-4B93-8EC9-E0FDA9D606C8" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.10.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37308B67-FA64-4858-AC66-EBC339180E11" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.10.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8B089E7-A9E4-4184-8AE3-3FE7D0E1A92D" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.10.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8685E03D-8377-4B30-9D41-DB6B926DC14D" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.10.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CDD34671-A2FF-4CCD-AE77-23FF323520E5" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.10.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13CE4AED-2939-47AA-8CC1-6D14069FDD98" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.10.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CE9EBED-E3AA-43AD-A47A-A1392DB424B0" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.10.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9028347B-DA89-433D-9843-22B6D4889696" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.10.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0E270F1-70EF-4DA0-ABAE-C8677CA48ED3" }, { "criteria": "cpe:2.3:a:tincan:phplist:2.10.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1832D080-E3C8-4634-907D-0717CD2DF284" } ], "operator": "OR" } ] } ]