CVE-2008-5184

CUPS < 1.3.8 - Cross-Site Request Forgery via RSS Subscription Functions

Title source: llm
STIX 2.1

Description

The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2008/11/19/3
Various Sources x_refsource_confirm
http://www.cups.org/str.php?L2774
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:028

Scores

EPSS 0.0367
EPSS Percentile 88.5%

Details

CWE
CWE-255
Status published
Products (32)
apple/cups 1.1
apple/cups 1.1.1
apple/cups 1.1.2
apple/cups 1.1.3
apple/cups 1.1.4
apple/cups 1.1.5
apple/cups 1.1.5-1
apple/cups 1.1.5-2
apple/cups 1.1.6
apple/cups 1.1.6-1
... and 22 more
Published Nov 21, 2008
Tracked Since Feb 18, 2026