PublicDate: 2008-04-21 13:05:00 UTC Candidate: CVE-2008-0165 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0165 Description: Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edit forms. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/bugs/227273 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_ikiwiki: upstream_ikiwiki: released (2.42) dapper_ikiwiki: DNE feisty_ikiwiki: needed (reached end-of-life) gutsy_ikiwiki: needed (reached end-of-life) hardy_ikiwiki: ignored (reached end-of-life) intrepid_ikiwiki: not-affected (2.46ubuntu1) jaunty_ikiwiki: not-affected (2.46ubuntu1) karmic_ikiwiki: not-affected (2.46ubuntu1) lucid_ikiwiki: not-affected (2.46ubuntu1) maverick_ikiwiki: not-affected (2.46ubuntu1) natty_ikiwiki: not-affected (2.46ubuntu1) oneiric_ikiwiki: not-affected (2.46ubuntu1) devel_ikiwiki: not-affected (2.46ubuntu1)