Vulnerability Description
Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fusetalk | Fusetalk | 2.0 |
Related Weaknesses (CWE)
References
- http://marc.info/?l=bugtraq&m=108377423825478&w=2Mailing List
- http://secunia.com/advisories/11555Broken LinkVendor Advisory
- http://securitytracker.com/id?1010080Broken LinkThird Party AdvisoryVDB Entry
- http://www.osvdb.org/5895Broken Link
- http://www.securityfocus.com/bid/10276Broken LinkExploitThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16080Third Party AdvisoryVDB Entry
- http://marc.info/?l=bugtraq&m=108377423825478&w=2Mailing List
- http://secunia.com/advisories/11555Broken LinkVendor Advisory
- http://securitytracker.com/id?1010080Broken LinkThird Party AdvisoryVDB Entry
- http://www.osvdb.org/5895Broken Link
- http://www.securityfocus.com/bid/10276Broken LinkExploitThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16080Third Party AdvisoryVDB Entry
FAQ
What is CVE-2004-1995?
CVE-2004-1995 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.
How severe is CVE-2004-1995?
CVE-2004-1995 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1995?
Check the references section above for vendor advisories and patch information. Affected products include: Fusetalk Fusetalk.