CVE-2008-5184
CUPS < 1.3.8 - Cross-Site Request Forgery via RSS Subscription Functions
Title source: llmDescription
The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.
References (5)
Core 5
Core References
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2008/11/19/3
Exploit x_refsource_misc
http://www.gnucitizen.org/blog/pwning-ubuntu-via-cups/
Various Sources x_refsource_confirm
http://www.cups.org/str.php?L2774
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00002.html
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:028
Scores
EPSS
0.0367
EPSS Percentile
88.5%
Details
CWE
CWE-255
Status
published
Products (32)
apple/cups
1.1
apple/cups
1.1.1
apple/cups
1.1.2
apple/cups
1.1.3
apple/cups
1.1.4
apple/cups
1.1.5
apple/cups
1.1.5-1
apple/cups
1.1.5-2
apple/cups
1.1.6
apple/cups
1.1.6-1
... and 22 more
Published
Nov 21, 2008
Tracked Since
Feb 18, 2026