CVE-2005-2411
tdiary - design error
EPSS 1.9%
Description
Cross-Site Request Forgery (CSRF) vulnerability in tDiary 2.1.1, and tDiary 2.0.1 and earlier, allows remote attackers to conduct actions as another user, and execute commands on the server, via a URL that is activated by the user.
How to fix CVE-2005-2411
To remediate CVE-2005-2411, upgrade the affected package to a fixed version below.
- Debian/tdiary—upgrade to 2.0.2-1 or later
- Debian/tdiary—upgrade to 2.0.1-1sarge1 or later
Is CVE-2005-2411 being exploited?
Low — EPSS is 1.9%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.0.2-1
- from 0, < 2.0.1-1sarge1