>> ikiwiki URL Processing Cross Site Request Forgery Vulnerabilities
Title : ikiwiki URL Processing Cross Site Request Forgery Vulnerabilities VUPEN ID : VUPEN/ADV-2008-1297 CVE ID : CVE-2008-0165
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-21
Technical Description
Multiple vulnerabilities have been identified in ikiwiki, which could be exploited to conduct cross site request forgery attacks. These issues are caused by a design error when processing URLs and user-supplied data, which could be exploited by attackers e.g. to cause logged-in users to change their passwords or modify wiki content via a specially crafted link.