Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-1462

Опубликовано: 15 мар. 2007
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by storing the password in the Value attribute of a password entry field, which allows attackers to steal the password by performing a "view source" or other operation to obtain the web page. NOTE: there are limited circumstances under which such an attack is feasible.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:redhat:linux:*:*:*:*:*:*:*:*
cpe:2.3:a:conga:conga:*:*:*:*:*:*:*:*

EPSS

Процентиль: 55%
0.00326
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

redhat
почти 19 лет назад

The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by storing the password in the Value attribute of a password entry field, which allows attackers to steal the password by performing a "view source" or other operation to obtain the web page. NOTE: there are limited circumstances under which such an attack is feasible.

github
почти 4 года назад

The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by storing the password in the Value attribute of a password entry field, which allows attackers to steal the password by performing a "view source" or other operation to obtain the web page. NOTE: there are limited circumstances under which such an attack is feasible.

EPSS

Процентиль: 55%
0.00326
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other