Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-1248

Опубликовано: 15 мая 2012
Источник: nvd
CVSS2: 5.1
EPSS Низкий

Описание

app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*
Версия до 1.6.15 (включая)
cpe:2.3:a:basercms:basercms:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.6:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.7:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.8:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.9:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.4:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.5:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.6:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.7:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.7.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.8:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.9:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.9.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.10:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11.2:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11.3:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11.4:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.12:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.13:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.13.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.13.6:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.14:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01244
Низкий

5.1 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain.

EPSS

Процентиль: 79%
0.01244
Низкий

5.1 Medium

CVSS2

Дефекты

CWE-264