Launchpad.net

CVE 2008-2571

Cross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly PHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas as administrators via a "modify quota" action.

See the CVE page on Mitre.org for more details.