Описание
Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.
Ссылки
- Exploit
- Third Party Advisory
- Third Party Advisory
- Exploit
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:openfind:mail2000:7.0:*:*:*:*:*:*:*
cpe:2.3:a:openfind:mail2000:8.0:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00175
Низкий
5.8 Medium
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-693
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 5.8
github
больше 1 года назад
Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.
EPSS
Процентиль: 39%
0.00175
Низкий
5.8 Medium
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-693
NVD-CWE-noinfo