Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cgm5-64xg-7qqq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the token from connections with picasaweb.google.com.

Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the token from connections with picasaweb.google.com.

EPSS

Процентиль: 83%
0.0188
Низкий

Связанные уязвимости

nvd
больше 14 лет назад

Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the token from connections with picasaweb.google.com.

EPSS

Процентиль: 83%
0.0188
Низкий