Cross-Site Request Forgery Vulnerability in BugTracker.NET by SourceForge
CVE-2008-0336
Currently unrated
What is CVE-2008-0336?
BugTracker.NET has multiple cross-site request forgery vulnerabilities that enable remote attackers to delete arbitrary bugs and execute various administrative actions. These vulnerabilities exist in versions prior to 2.7.2 and can be exploited through unspecified vectors, likely involving certain pages such as delete_*.aspx, massedit.aspx, subscribe.aspx, flag.aspx, and relationships.aspx. This puts the integrity of bug management at risk, allowing unauthorized changes to the system.
