Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2001-1537

Опубликовано: 31 дек. 2001
Источник: debian
EPSS Низкий

Описание

The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.

Примечания

  • current twig package seems to have secure cookies enabled

  • still uses "basic" security setting.

EPSS

Процентиль: 43%
0.00204
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
больше 23 лет назад

The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.

CVSS3: 7.5
github
около 3 лет назад

The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.

EPSS

Процентиль: 43%
0.00204
Низкий