CVE Vulnerabilities

CVE-2006-2495

Published: May 20, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag.

Affected Software

NameVendorStart VersionEnd Version
SerendipityS9y0.3 (including)0.3 (including)
SerendipityS9y0.4 (including)0.4 (including)
SerendipityS9y0.5 (including)0.5 (including)
SerendipityS9y0.5_pl1 (including)0.5_pl1 (including)
SerendipityS9y0.6 (including)0.6 (including)
SerendipityS9y0.6_pl3 (including)0.6_pl3 (including)
SerendipityS9y0.7 (including)0.7 (including)
SerendipityS9y0.7.1 (including)0.7.1 (including)
SerendipityS9y0.8 (including)0.8 (including)
SerendipityS9y0.8.1 (including)0.8.1 (including)
SerendipityS9y0.8.2 (including)0.8.2 (including)
SerendipityS9y0.8.3 (including)0.8.3 (including)
SerendipityS9y0.8.4 (including)0.8.4 (including)
SerendipityS9y0.8.5 (including)0.8.5 (including)
SerendipityS9y0.9 (including)0.9 (including)
SerendipityS9y0.9.1 (including)0.9.1 (including)
SerendipityS9y1.0_beta1 (including)1.0_beta1 (including)
SerendipityS9y1.0_beta2 (including)1.0_beta2 (including)

References