Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Robocoder

#26968of 53,608
9.3Total CVSS
Vulnerabilities · 2
Medium
2
PT-2011-2320
4.3
2011-01-10
Piwik · Piwik · CVE-2011-0399
**Name of the Vulnerable Software and Affected Versions** Piwik versions prior to 1.1 **Description** The issue allows remote attackers to conduct clickjacking attacks via a crafted web site, making it easier to perform malicious actions by rendering the login form inside a frame in a third-party HTML document. **Recommendations** For versions prior to 1.1, update to version 1.1 or later to prevent the rendering of the login form inside a frame in a third-party HTML document and mitigate the risk of clickjacking attacks.
PT-2011-2321
5.0
2011-01-10
Piwik · Piwik · CVE-2011-0400
**Name of the Vulnerable Software and Affected Versions** Piwik versions prior to 1.1 **Description** The issue allows remote attackers to capture the session cookie by intercepting its transmission within an http session, as the secure flag for the session cookie is not set in an https session. **Recommendations** For versions prior to 1.1, update to version 1.1 or later to set the secure flag for the session cookie in an https session.