CVE Database
/

CVE-2008-7193

Back to search

CVE-2008-7193

Published: Sep 9, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by reading the PHPKITSID parameter from the HTTP Referer and using it in a request to (1) modify the user profile via upload_files/include.php or (2) create a new administrator via upload_files/pk/include.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

phpkit-include-csrf(40033)
vdb-entry
x_refsource_XF
50998
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now