Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mark Ramm-Christensen

#17945of 53,633
15Total CVSS
Vulnerabilities · 2
High
2
PT-2010-1816
7.5
2010-11-05
Turbogears · Turbogears2 · CVE-2009-5014
**Name of the Vulnerable Software and Affected Versions** TurboGears2 versions prior to 2.0.2 **Description** The default quickstart configuration has a weak cookie salt, making it easier for remote attackers to bypass authentication via a forged authorization cookie. **Recommendations** For versions prior to 2.0.2, update to version 2.0.2 or later to resolve the issue.
PT-2010-1817
7.5
2010-11-05
Turbogears · Turbogears2 · CVE-2009-5015
**Name of the Vulnerable Software and Affected Versions** TurboGears2 versions prior to 2.0.2 **Description** The issue in TurboGears2 concerns the URL dispatch mechanism, which exposes controller methods even when an @expose decoration is not used. This has an unspecified impact and attack vectors. **Recommendations** For versions prior to 2.0.2, update to version 2.0.2 or later to resolve the issue.