Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-3359

Опубликовано: 31 мар. 2014
Источник: nvd
CVSS2: 3.7
EPSS Низкий

Описание

Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:conga:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00142
Низкий

3.7 Low

CVSS2

Дефекты

CWE-255

Связанные уязвимости

redhat
больше 12 лет назад

Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.

github
больше 3 лет назад

Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.

oracle-oval
больше 12 лет назад

ELSA-2013-0128: conga security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 35%
0.00142
Низкий

3.7 Low

CVSS2

Дефекты

CWE-255