Loading...
Loading...
PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by reading the PHPKITSID parameter from the HTTP Referer and using it in a request to (1) modify the user profile via upload_files/include.php or (2) create a new administrator via upload_files/pk/include.php.
September 9, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2008-7193
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.