Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-1638
Description:Multiple cross-site request forgery (CSRF) vulnerabilities in the check_csrftoken function in lib/lib.inc.php in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote attackers to perform unauthorized actions as an arbitrary user via the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Notes, (5) Search, (6) Mail, or (7) Filemanager module; the (9) summary page; or unspecified other files.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-1638
Bugtraq: 20070314 n.runs-SA-2007.005 - PHProjekt 5.2.0 - Cross Site Request Forgery (Google Search)
http://www.securityfocus.com/archive/1/462786/100/100/threaded
http://security.gentoo.org/glsa/glsa-200706-07.xml
http://www.nruns.de/security_advisory_phprojekt_csrf.php
http://osvdb.org/35162
http://secunia.com/advisories/24509
http://secunia.com/advisories/25748
http://securityreason.com/securityalert/2477
XForce ISS Database: phprojekt-multiple-modules-csrf(32989)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32989




© 1998-2025 E-Soft Inc. All rights reserved.