This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.

INFORMATION

Name : CVE-2009-1339 First Publication : 2009-04-30
Severity : Medium Last Modification : 2009-05-14

SCORING CVSS v2

Cvss Base Score : 6 Attack Range : Network
Cvss Impact Score : 6.4 Attack Complexity : Medium
Cvss Expoit Score : 6.8 Authentification : Requires single instance

Calculate full CVSS 2.0 Vectors scores

DETAIL

Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL for a save script in the SRC attribute of an IMG element, a related issue to CVE-2009-1434.



CWE COMMON WEAKNESS ENUMERATION

CPE COMMON PLATFORM ENUMERATION

OPEN SOURCE VULNERABILTY DATABASE (OSVDB)

54175 : TWiki Page Update User Authentication Bypass CSRF.


SECONDARY(S) SOURCE(S)