PT-2014-2855 · Ddsn Interactive · Ddsn Interactive Cm3 Acora Cms

Publicado

2014-06-06

·

Atualizado

2014-06-09

·

CVE-2013-4725

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions DDSN Interactive cm3 Acora CMS versions 5.5.0/1b-p1 through 6.0.6/1a
Description The issue allows remote attackers to capture an unspecified cookie by intercepting its transmission within an http session, as the cookie is not set with the secure flag in an https session.
Recommendations For versions 5.5.0/1b-p1 through 6.0.6/1a, consider setting the secure flag for the unspecified cookie to prevent it from being transmitted over http sessions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4725

Produtos afetados

Ddsn Interactive Cm3 Acora Cms