Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2012-0826

EPSS 0.14% · P33
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2012-0826

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Drupal Aggregator模块跨站请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。Aggregator是其中的一个聚合器模块,它支持的Feed(用来接收信息来源更新的接口)类型包括RSS、RDF、Atom。 Drupal 6.23之前的6.x版本和7.11之前的7.x版本中的Aggregator模块中存在跨站请求伪造漏洞。远程攻击者可利用该漏洞劫持任意用户请求的身份验证,也可能造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2012-0826

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2012-0826

登录查看更多情报信息。

Same Patch Batch · n/a · 2013-10-28 · 28 CVEs total

CVE-2013-5744Feng Office ‘index.php’ 跨站脚本漏洞
CVE-2013-6285Tyler Technologies TaxWeb 信息泄露漏洞
CVE-2013-6020Tyler Technologies TaxWeb 信息泄露漏洞
CVE-2013-6019Tyler Technologies TaxWeb 跨站脚本漏洞
CVE-2013-6018Tyler Technologies TaxWeb 跨站请求伪造漏洞
CVE-2013-5430IBM Security AppScan Enterprise Jazz Team Server组件信任管理漏洞
CVE-2013-2186Apache Commons FileUpload 输入验证错误漏洞
CVE-2013-2102Red Hat JBoss Portal JGroups Diagnostics Service 信息泄露漏洞
CVE-2013-1056X.Org X Server Xephyr 本地拒绝服务漏洞
CVE-2012-4572Red Hat JBoss JBoss EAP 身份验证安全绕过漏洞
CVE-2012-4529Red Hat JBoss Web 会话ID信息泄露漏洞
CVE-2013-6289TYPO3 Apache Solr for TYPO3扩展跨站脚本漏洞
CVE-2013-6288TYPO3 Apache Solr for TYPO3扩展安全漏洞
CVE-2013-6012Juniper Junos 未授权访问漏洞
CVE-2013-6014Juniper Junos 信息泄露漏洞
CVE-2013-4402GnuPG 拒绝服务漏洞
CVE-2013-4394systemd X Keyboard Extension Processing 本地提权漏洞
CVE-2013-4393systemd ‘journald’功能拒绝服务漏洞
CVE-2013-4392systemd 后置链接漏洞
CVE-2013-4391systemd ‘journald-native.c’远程整数溢出漏洞

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2012-0826

No comments yet


Leave a comment