Описание
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
Дополнительная информация
Статус:
Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=468181mantis: logout without unsetting session cookie
EPSS
Процентиль: 77%
0.01112
Низкий
Связанные уязвимости
ubuntu
около 17 лет назад
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
nvd
около 17 лет назад
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
debian
около 17 лет назад
Mantis before 1.1.3 does not unset the session cookie during logout, w ...
github
больше 3 лет назад
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
EPSS
Процентиль: 77%
0.01112
Низкий