Vulnerability Details CVE-2006-2495
Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.6%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2006-2495
-
cpe:2.3:a:s9y:serendipity:0.3
-
cpe:2.3:a:s9y:serendipity:0.4
-
cpe:2.3:a:s9y:serendipity:0.5
-
cpe:2.3:a:s9y:serendipity:0.5_pl1
-
cpe:2.3:a:s9y:serendipity:0.6
-
cpe:2.3:a:s9y:serendipity:0.6_pl3
-
cpe:2.3:a:s9y:serendipity:0.7
-
cpe:2.3:a:s9y:serendipity:0.7.1
-
cpe:2.3:a:s9y:serendipity:0.8
-
cpe:2.3:a:s9y:serendipity:0.8.1
-
cpe:2.3:a:s9y:serendipity:0.8.2
-
cpe:2.3:a:s9y:serendipity:0.8.3
-
cpe:2.3:a:s9y:serendipity:0.8.4
-
cpe:2.3:a:s9y:serendipity:0.8.5
-
cpe:2.3:a:s9y:serendipity:0.9
-
cpe:2.3:a:s9y:serendipity:0.9.1
-
cpe:2.3:a:s9y:serendipity:1.0_beta1
-
cpe:2.3:a:s9y:serendipity:1.0_beta2