{"api_version":"1","generated_at":"2026-07-23T10:17:45+00:00","cve":"CVE-2010-0709","urls":{"html":"https://cve.report/CVE-2010-0709","api":"https://cve.report/api/cve/CVE-2010-0709.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-0709","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-0709"},"summary":{"title":"CVE-2010-0709","description":"Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authentication of users or administrators for requests that change the email address or password via the user action to index.php, and (2) hijack the authentication of the administrator for requests that create a new user via the admin/modules/user/new action to limny/index.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-02-25 20:30:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-352","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.exploit-db.com/exploits/11477","name":"http://www.exploit-db.com/exploits/11477","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Limny 2.0 - Cross-Site Request Forgery (Change Email and Password) - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38616","name":"http://secunia.com/advisories/38616","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA38616 - Limny Cross-Site Request Forgery Vulnerability - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56318","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56318","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.limny.org/","name":"http://www.limny.org/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Limny - content management framerwok","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/11478","name":"http://www.exploit-db.com/exploits/11478","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Limny 2.0 - Cross-Site Request Forgery (Create Admin User) - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/62389","name":"http://osvdb.org/62389","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-0709","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-0709","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"709","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"limny","cpe5":"limny","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:59:38.604Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"11478","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/11478"},{"name":"limny-admin-csrf(56318)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56318"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.limny.org/"},{"name":"38616","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38616"},{"name":"11477","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/11477"},{"name":"62389","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/62389"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-02-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authentication of users or administrators for requests that change the email address or password via the user action to index.php, and (2) hijack the authentication of the administrator for requests that create a new user via the admin/modules/user/new action to limny/index.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"11478","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/11478"},{"name":"limny-admin-csrf(56318)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56318"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.limny.org/"},{"name":"38616","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38616"},{"name":"11477","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/11477"},{"name":"62389","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/62389"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-0709","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authentication of users or administrators for requests that change the email address or password via the user action to index.php, and (2) hijack the authentication of the administrator for requests that create a new user via the admin/modules/user/new action to limny/index.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"11478","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/11478"},{"name":"limny-admin-csrf(56318)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56318"},{"name":"http://www.limny.org/","refsource":"CONFIRM","url":"http://www.limny.org/"},{"name":"38616","refsource":"SECUNIA","url":"http://secunia.com/advisories/38616"},{"name":"11477","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/11477"},{"name":"62389","refsource":"OSVDB","url":"http://osvdb.org/62389"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-0709","datePublished":"2010-02-25T20:00:00.000Z","dateReserved":"2010-02-25T00:00:00.000Z","dateUpdated":"2024-08-07T00:59:38.604Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-02-25 20:30:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-352","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:limny:limny:2.0:*:*:*:*:*:*:*","matchCriteriaId":"7270DDB4-71DE-4B3D-B62D-27716684A28E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"709","Ordinal":"1","Title":"CVE-2010-0709","CVE":"CVE-2010-0709","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"709","Ordinal":"1","NoteData":"Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authentication of users or administrators for requests that change the email address or password via the user action to index.php, and (2) hijack the authentication of the administrator for requests that create a new user via the admin/modules/user/new action to limny/index.php.","Type":"Description","Title":"CVE-2010-0709"},{"CveYear":"2010","CveId":"709","Ordinal":"2","NoteData":"2010-02-25","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"709","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}