Описание
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:joomla:joomla\!:1.5.8:*:*:*:*:*:*:*
EPSS
Процентиль: 4%
0.00018
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-319
Связанные уязвимости
CVSS3: 7.5
github
почти 4 года назад
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
EPSS
Процентиль: 4%
0.00018
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-319