CVE-2006-3479: CSRF
Published Jul 10, 2006
·Updated
Cross-site request forgery (CSRF) vulnerability in the delblock function in modules/Admin/block.php in Nuked-Klan 1.7.5 and earlier and 1.7 SP4.2 allows remote attackers to delete arbitrary "blocks" via a link with a modified bid parameter in a delblock op on the block page in index.php.
Affected Software
2 affected components
Nuked-Klan Nuked-KlaN<=1.7.5
Nuked-Klan Nuked-KlaN=1.7_sp4.2
Event History
Jul 10, 2006
CVE Published
08:05 PM
Jul 11, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3479?
CVE-2006-3479 is considered a high severity vulnerability due to its potential for unauthorized block deletion.
2
How do I fix CVE-2006-3479?
To fix CVE-2006-3479, upgrade to a version of Nuked-Klan newer than 1.7.5 or 1.7 SP4.2.
3
What type of vulnerability is CVE-2006-3479?
CVE-2006-3479 is categorized as a Cross-Site Request Forgery (CSRF) vulnerability.
4
What versions of Nuked-Klan are affected by CVE-2006-3479?
CVE-2006-3479 affects Nuked-Klan versions 1.7.5 and earlier, as well as 1.7 SP4.2.
5
What can attackers achieve with CVE-2006-3479?
Attackers can remotely delete arbitrary blocks using a manipulated del_block parameter.