Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-3584

Опубликовано: 23 дек. 2009
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sql-ledger:sql-ledger:2.8.24:*:*:*:*:*:*:*

EPSS

Процентиль: 55%
0.00319
Низкий

5 Medium

CVSS2

Дефекты

CWE-16

Связанные уязвимости

ubuntu
почти 16 лет назад

SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

debian
почти 16 лет назад

SQL-Ledger 2.8.24 does not set the secure flag for the session cookie ...

github
больше 3 лет назад

SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

EPSS

Процентиль: 55%
0.00319
Низкий

5 Medium

CVSS2

Дефекты

CWE-16