CVE-2009-3022

Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for requests that modify configuration or change content via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:itd-inc:bingo\!cms:*:-:commercial:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.2:-:*:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.2:*:*:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.1:-:core:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.1:-:commercial:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.0:-:commercial:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.0:-:*:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.1:b:*:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.1:a:core:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.0:a:core:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.0:a:commercial:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:*:-:core:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.1:a:commercial:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.1:a:*:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.0:a:*:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.0:-:core:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.1:b:core:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.1:b:commercial:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.1:-:*:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.1:*:*:*:*:*:*:*
cpe:2.3:a:itd-inc:bingo\!cms:1.0:*:*:*:*:*:*:*

Information

Published : 2009-08-31 20:30

Updated : 2017-08-17 01:31


NVD link : CVE-2009-3022

Mitre link : CVE-2009-3022


JSON object : View

Products Affected

itd-inc

  • bingo\!cms
CWE
CWE-352

Cross-Site Request Forgery (CSRF)