CVE-2008-0336 (Bugtracker.NET) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2008-0336 (Bugtracker.NET)


Heap
18-01-08, 15:44
Multiple cross-site request forgery (CSRF) vulnerabilities in BugTracker.NET before 2.7.2 allow remote attackers to delete arbitrary bugs and perform other administrative tasks via unspecified vectors, possibly related to delete_*.aspx pages, and massedit.aspx, subscribe.aspx, flag.aspx, and relationships.aspx.

More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0336)