CVE-2005-2411
EPSS 0.93%tdiary - design error
Published: 8/1/2005Modified: 4/28/2026
Description
Cross-Site Request Forgery (CSRF) vulnerability in tDiary 2.1.1, and tDiary 2.0.1 and earlier, allows remote attackers to conduct actions as another user, and execute commands on the server, via a URL that is activated by the user.
Affected packages (2)
- Debian/tdiaryfrom 0, < 2.0.2-1
- Debian/tdiaryfrom 0, < 2.0.1-1sarge1