Unrated severityNVD Advisory· Published Feb 14, 2012· Updated Apr 29, 2026
CVE-2010-5084
CVE-2010-5084
Description
The cross-site request forgery (CSRF) protection mechanism in e107 before 0.7.23 uses a predictable random token based on the creation date of the administrator account, which allows remote attackers to hijack the authentication of administrators for requests that add new users via e107_admin/users.php.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- secunia.com/advisories/41034nvdVendor Advisory
- e107.org/comment.phpnvd
- www.madirish.netnvd
- www.securitytracker.com/idnvd
News mentions
0No linked articles in our index yet.