The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows remote attackers to conduct CSRF attacks.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2007-03-20 20:19
Updated : 2024-02-14 01:17
NVD link : CVE-2007-1520
Mitre link : CVE-2007-1520
CVE.ORG link : CVE-2007-1520
JSON object : View
Products Affected
phpnuke
- php-nuke
CWE
CWE-352
Cross-Site Request Forgery (CSRF)