CVE-2011-5223
published 2012-10-25CVE-2011-5223: Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0.8.7i allows remote attackers to hijack the authentication of unspecified…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.12%
80.0th percentile
Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0.8.7i allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | <= 0.8.7h | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v49p-p426-xv6r: Cross-site request forgery (CSRF) vulnerability in logout
ghsa_unreviewed·2022-05-17
CVE-2011-5223 [MEDIUM] CWE-79 GHSA-v49p-p426-xv6r: Cross-site request forgery (CSRF) vulnerability in logout
Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0.8.7i allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
OSV
CVE-2011-5223: Cross-site request forgery (CSRF) vulnerability in logout
osv·2012-10-25·CVSS 4.3
CVE-2011-5223 [MEDIUM] CVE-2011-5223: Cross-site request forgery (CSRF) vulnerability in logout
Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0.8.7i allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Debian
CVE-2011-5223: cacti - Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0....
vendor_debian·2011·CVSS 4.3
CVE-2011-5223 [MEDIUM] CVE-2011-5223: cacti - Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0....
Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0.8.7i allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Scope: local
bookworm: resolved (fixed in 0.8.7i-1)
bullseye: resolved (fixed in 0.8.7i-1)
forky: resolved (fixed in 0.8.7i-1)
sid: resolved (fixed in 0.8.7i-1)
trixie: resolved (fixed in 0.8.7i-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.cacti.net/view.php?id=2062http://forums.cacti.net/viewtopic.php?f=21&t=44116http://forums.cacti.net/viewtopic.php?f=4&t=45871http://secunia.com/advisories/47195http://www.securityfocus.com/bid/51048https://exchange.xforce.ibmcloud.com/vulnerabilities/71792http://bugs.cacti.net/view.php?id=2062http://forums.cacti.net/viewtopic.php?f=21&t=44116http://forums.cacti.net/viewtopic.php?f=4&t=45871http://secunia.com/advisories/47195http://www.securityfocus.com/bid/51048https://exchange.xforce.ibmcloud.com/vulnerabilities/71792
2012-10-25
Published