CVE-2006-2495: CSRF
Published May 20, 2006
·Updated
Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag.
Affected Software
18 affected components
S9Y serendipity=0.5
S9Y serendipity=0.4
S9Y serendipity=0.8.5
S9Y serendipity=0.7
S9Y serendipity=0.8.3
S9Y serendipity=0.8.4
S9Y serendipity=0.8.2
S9Y serendipity=0.7.1
S9Y serendipity=0.5_pl1
S9Y serendipity=1.0_beta1
S9Y serendipity=1.0_beta2
S9Y serendipity=0.8.1
S9Y serendipity=0.8
S9Y serendipity=0.3
S9Y serendipity=0.6_pl3
S9Y serendipity=0.9.1
S9Y serendipity=0.9
S9Y serendipity=0.6
Remediation
Event History
May 20, 2006
CVE Published
03:02 AM
CVE Published
via MITRE·06:59 AM
Data Sourced
via MITRE·06:59 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2495?
CVE-2006-2495 has a medium severity rating that allows unauthorized actions through cross-site request forgery.
2
How do I fix CVE-2006-2495?
To fix CVE-2006-2495, upgrade to Serendipity version 1.0-beta3 or later, which mitigates the CSRF vulnerability.
3
What versions of Serendipity are affected by CVE-2006-2495?
CVE-2006-2495 affects multiple versions of Serendipity including all versions prior to 1.0-beta3.
4
What kind of attacks does CVE-2006-2495 allow?
CVE-2006-2495 allows remote attackers to carry out unauthorized actions on behalf of a logged-in user.
5
Is there a known exploit for CVE-2006-2495?
Yes, CVE-2006-2495 is associated with known exploit techniques that leverage cross-site request forgery.