Candidate: CVE-2010-5285 PublicDate: 2012-11-26 23:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5285 http://www.exploit-db.com/exploits/15240 http://www.anatoliasecurity.com/adv/as-adv-2010-003.txt http://secunia.com/advisories/41805 http://packetstormsecurity.org/1010-exploits/collabtive-xssxsrf.txt Description: Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrators for requests that add administrative users via the edituser action. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_collabtive: upstream_collabtive: released (0.7) hardy_collabtive: DNE lucid_collabtive: DNE oneiric_collabtive: released (0.7-1.1) precise_collabtive: released (0.7-1.1) quantal_collabtive: released (0.7.6-1) devel_collabtive: released (0.7.6-1)