PT-2008-4013 · Cre Loaded · Cre Loaded

Published

2008-06-05

·

Updated

2024-02-14

·

CVE-2008-2558

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CRE Loaded versions 6.2.13.1 and earlier
Description The issue is related to the handling of cookies over HTTPS. Specifically, the software does not set the "Secure" attribute for cookies sent over HTTPS, which could allow remote attackers to sniff the cookies if they are sent over HTTP.
Recommendations For CRE Loaded versions 6.2.13.1 and earlier, ensure that the "Secure" attribute is set for cookies sent over HTTPS to prevent potential cookie sniffing attacks.

Fix

Weakness Enumeration

Related Identifiers

CVE-2008-2558

Affected Products

Cre Loaded