~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2011-5196

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2011-5196
2
 
PublicDate: 2012-09-23
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5196
5
 
 http://www.exploit-db.com/exploits/18266
6
 
 http://secunia.com/advisories/47330
7
 
 http://osvdb.org/77995
8
 
Description:
9
 
 Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload
10
 
 in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows
11
 
 remote attackers to hijack the authentication of administrators for
12
 
 requests that upload PHP files.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
Bugs:
16
 
Priority: high
17
 
Discovered-by:
18
 
Assigned-to:
19
 
 
20
 
Patches_ojs:
21
 
upstream_ojs: needs-triage
22
 
hardy_ojs: DNE
23
 
lucid_ojs: DNE
24
 
natty_ojs: ignored (reached end-of-life)
25
 
oneiric_ojs: ignored (reached end-of-life)
26
 
precise_ojs: DNE
27
 
quantal_ojs: DNE
28
 
raring_ojs: DNE
29
 
devel_ojs: DNE