CVE-2008-1172: CSRF
Published Mar 6, 2008
·Updated
Cross-site request forgery (CSRF) vulnerabilities in account-inbox.php in TorrentTrader Classic 1.08 allow remote attackers to perform certain actions as other users, as demonstrated by sending messages.
Affected Software
2 affected components
TorrentTrader TorrentTrader Classic=1.08
TorrentTrader TorrentTrader=1.08
Event History
Mar 6, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1172?
CVE-2008-1172 is classified as a moderate severity vulnerability due to its potential to allow unauthorized actions by remote attackers.
2
How do I fix CVE-2008-1172?
To fix CVE-2008-1172, developers should implement anti-CSRF tokens in forms to prevent cross-site request forgery.
3
What software is affected by CVE-2008-1172?
CVE-2008-1172 affects TorrentTrader Classic version 1.08 and TorrentTrader version 1.08.
4
What type of vulnerability is CVE-2008-1172?
CVE-2008-1172 is a cross-site request forgery (CSRF) vulnerability.
5
What impact can CVE-2008-1172 have on users?
CVE-2008-1172 can allow attackers to perform actions on behalf of authenticated users, compromising user accounts.