PT-2014-2855 · Ddsn Interactive · Ddsn Interactive Cm3 Acora Cms

Published

2014-06-06

·

Updated

2014-06-09

·

CVE-2013-4725

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions DDSN Interactive cm3 Acora CMS versions 5.5.0/1b-p1 through 6.0.6/1a
Description The issue allows remote attackers to capture an unspecified cookie by intercepting its transmission within an http session, as the cookie is not set with the secure flag in an https session.
Recommendations For versions 5.5.0/1b-p1 through 6.0.6/1a, consider setting the secure flag for the unspecified cookie to prevent it from being transmitted over http sessions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4725

Affected Products

Ddsn Interactive Cm3 Acora Cms