PT-2008-5423 · Open Source Matters · Joomla!

Hanno Boeck

·

Publicado

2008-12-19

·

Atualizado

2024-01-25

·

CVE-2008-4122

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Joomla! version 1.5.8
Description The issue makes it easier for remote attackers to capture the session cookie by intercepting its transmission within an http session, as the secure flag is not set for the session cookie in an https session.
Recommendations For version 1.5.8, consider updating the session cookie handling to set the secure flag when transmitting over https to prevent interception.

Correção

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4122

Produtos afetados

Joomla!