Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Robocoder

#26957de 53,630
9.3CVSS total
Vulnerabilidades · 2
Média
2
PT-2011-2320
4.3
2011-01-10
Piwik · Piwik · CVE-2011-0399
**Name of the Vulnerable Software and Affected Versions** Piwik versions prior to 1.1 **Description** The issue allows remote attackers to conduct clickjacking attacks via a crafted web site, making it easier to perform malicious actions by rendering the login form inside a frame in a third-party HTML document. **Recommendations** For versions prior to 1.1, update to version 1.1 or later to prevent the rendering of the login form inside a frame in a third-party HTML document and mitigate the risk of clickjacking attacks.
PT-2011-2321
5.0
2011-01-10
Piwik · Piwik · CVE-2011-0400
**Name of the Vulnerable Software and Affected Versions** Piwik versions prior to 1.1 **Description** The issue allows remote attackers to capture the session cookie by intercepting its transmission within an http session, as the secure flag for the session cookie is not set in an https session. **Recommendations** For versions prior to 1.1, update to version 1.1 or later to set the secure flag for the session cookie in an https session.