Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-0535
Description:Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change account privileges via an edit access_permissions action to index.php.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-0535
20110201 Zikula CMS 1.2.4 <= Cross Site Request Forgery (CSRF) Vulnerability
http://seclists.org/fulldisclosure/2011/Feb/0
43114
http://secunia.com/advisories/43114
70751
http://www.osvdb.org/70751
8067
http://securityreason.com/securityalert/8067
[oss-security] 20110201 CVE Request: Zikula CMS 1.2.4 <= Cross Site Request Forgery (CSRF) Vulnerability
http://openwall.com/lists/oss-security/2011/02/01/1
[oss-security] 20110203 Re: CVE Request: Zikula CMS 1.2.4 <= Cross Site Request Forgery (CSRF) Vulnerability
http://openwall.com/lists/oss-security/2011/02/03/1
http://bl0g.yehg.net/2011/02/zikula-cms-124-cross-site-request.html
http://bl0g.yehg.net/2011/02/zikula-cms-124-cross-site-request.html
http://code.zikula.org/core12/browser/tags/Zikula-1.2.5/src/docs/CHANGELOG
http://code.zikula.org/core12/browser/tags/Zikula-1.2.5/src/docs/CHANGELOG
http://community.zikula.org/index.php?module=News&func=display&sid=3041&title=zikula-1.2.5-released
http://community.zikula.org/index.php?module=News&func=display&sid=3041&title=zikula-1.2.5-released




© 1998-2025 E-Soft Inc. All rights reserved.