Vulnerability Description
The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows remote attackers to conduct CSRF attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpnuke | Php-Nuke | <= 8.0 |
Related Weaknesses (CWE)
References
- http://osvdb.org/34501
- http://phpfi.com/214668ExploitURL Repurposed
- http://secunia.com/advisories/24629Vendor Advisory
- http://www.securityfocus.com/archive/1/462308/100/100/threaded
- http://www.securityfocus.com/archive/1/462575/100/0/threaded
- http://www.securityfocus.com/archive/1/462727/100/0/threaded
- http://www.ush.it/2007/03/09/php-nuke-wild-post-xss/Exploit
- http://www.wisec.it/ush/phpnukexss.htmlExploit
- http://osvdb.org/34501
- http://phpfi.com/214668ExploitURL Repurposed
- http://secunia.com/advisories/24629Vendor Advisory
- http://www.securityfocus.com/archive/1/462308/100/100/threaded
- http://www.securityfocus.com/archive/1/462575/100/0/threaded
- http://www.securityfocus.com/archive/1/462727/100/0/threaded
- http://www.ush.it/2007/03/09/php-nuke-wild-post-xss/Exploit
FAQ
What is CVE-2007-1520?
CVE-2007-1520 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows remote attackers to con...
How severe is CVE-2007-1520?
CVE-2007-1520 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-1520?
Check the references section above for vendor advisories and patch information. Affected products include: Phpnuke Php-Nuke.