« Volver al listado

CVE-2008-3885

Estado: ModificadaMedia (6.8)—

Vulnerabilidad de falsificación de petición en sitios cruzados (CSFR) en Blogn (BURO GUN) 1.9.7 y anteriores, permite a atacantes remotos realizar modificaciones en el contenido a través de vectores no especificados, haciéndose pasar por usuarios de su elección. NOTA: algunos de estos detalles han sido obtenidos de fuentes de terceros.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-3885",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-09-02T15:41:00.000",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN84125369/index.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/31662",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.blogn.org/index.php?e=172",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44769",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN84125369/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/31662",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.blogn.org/index.php?e=172",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44769",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site request forgery (CSRF) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make content modifications. NOTE: some of these details are obtained from third party information."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de falsificación de petición en sitios cruzados (CSFR) en Blogn (BURO GUN) 1.9.7 y anteriores, permite a atacantes remotos realizar modificaciones en el contenido a través de vectores no especificados, haciéndose pasar por usuarios de su elección. NOTA: algunos de estos detalles han sido obtenidos de fuentes de terceros."
    }
  ],
  "lastModified": "2026-06-16T22:56:44.363",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:blogn:blogn:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20171619-1350-463F-A52C-FEDDB5F228B8",
              "versionEndIncluding": "1.9.7"
            },
            {
              "criteria": "cpe:2.3:a:blogn:blogn:1.9.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F089C16C-161B-4315-B0A0-FA12984417C5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}