Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-3909 (django)

BugsAlert Home > CVE-2008-3909 (django)
 
 

The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.




Original Source: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3909

Learn more about CVE-2008-3909 (django)
 
Tags: cve-2008-3909 django

Related Items

      CVE-2008-2707 (network_interface_controller)

      IBM Lotus Domino Web Server Component Unspecified Vulnerability

      CVE-2008-3659 (PHP)

      FrSIRT - Slackware Security Update Fixes Ruby Code Execution Vulnerabilities

      Vuln: IBM WebSphere MQ Multiple Unspecified Remote Memory Corruption Vulnerabilities

      CVE-2008-1561 (Wireshark)

      Vuln: Sun JSSE SSL/TLS Handshake Processing Denial Of Service Vulnerability

 

Pixel