First published: Mon Jul 10 2006(Updated: )
Cross-site request forgery (CSRF) vulnerability in the del_block function in modules/Admin/block.php in Nuked-Klan 1.7.5 and earlier and 1.7 SP4.2 allows remote attackers to delete arbitrary "blocks" via a link with a modified bid parameter in a del_block op on the block page in index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nuked-klan Partenaires Module | <=1.7.5 | |
Nuked-klan Partenaires Module | =1.7_sp4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3479 is considered a high severity vulnerability due to its potential for unauthorized block deletion.
To fix CVE-2006-3479, upgrade to a version of Nuked-Klan newer than 1.7.5 or 1.7 SP4.2.
CVE-2006-3479 is categorized as a Cross-Site Request Forgery (CSRF) vulnerability.
CVE-2006-3479 affects Nuked-Klan versions 1.7.5 and earlier, as well as 1.7 SP4.2.
Attackers can remotely delete arbitrary blocks using a manipulated del_block parameter.