CVE-2008-0165: CSRF
Published Apr 20, 2008
·Updated
Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edit forms.
Affected Software
1 affected component
Ikiwiki ikiwiki<=2.41
Event History
Apr 20, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0165?
CVE-2008-0165 is categorized as a medium severity vulnerability due to the potential for unauthorized preference modifications.
2
How do I fix CVE-2008-0165?
To fix CVE-2008-0165, upgrade Ikiwiki to version 2.42 or later.
3
What types of attacks are associated with CVE-2008-0165?
CVE-2008-0165 is associated with cross-site request forgery (CSRF) attacks that allow modification of user preferences.
4
Who is affected by CVE-2008-0165?
CVE-2008-0165 affects all versions of Ikiwiki prior to 2.42.
5
What can attackers do with CVE-2008-0165?
Attackers exploiting CVE-2008-0165 can modify user preferences, including sensitive information like passwords.