Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-8684

Опубликовано: 19 сент. 2017
Источник: debian

Описание

CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
codeigniteritppackage

Связанные уязвимости

CVSS3: 9.8
nvd
больше 8 лет назад

CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.

CVSS3: 9.8
github
больше 3 лет назад

CodeIgniter and Kohana vulnerable to PHP Object Injection