Candidate: CVE-2015-5660 PublicDate: 2015-10-16 01:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5660 http://jvndb.jvn.jp/jvndb/JVNDB-2015-000126 http://jvn.jp/en/jp/JVN92520335/index.html http://extplorer.net/news/18 Description: Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_extplorer: upstream_extplorer: released (2.1.8) precise_extplorer: ignored (reached end-of-life) precise/esm_extplorer: DNE (precise was needs-triage) trusty_extplorer: released (2.1.0b6+dfsg.3-4+deb7u3build0.14.04.1) trusty/esm_extplorer: DNE (trusty was released [2.1.0b6+dfsg.3-4+deb7u3build0.14.04.1]) vivid_extplorer: ignored (reached end-of-life) vivid/stable-phone-overlay_extplorer: DNE vivid/ubuntu-core_extplorer: DNE wily_extplorer: released (2.1.0b6+dfsg.3-4+deb7u3build0.15.10.1) xenial_extplorer: released (2.1.0b6+dfsg.3-4+deb7u3ubuntu0.1) yakkety_extplorer: DNE zesty_extplorer: DNE devel_extplorer: DNE