Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-4244

Опубликовано: 31 авг. 2006
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value.

РелизСтатусПримечание
dapper

ignored

end of life
devel

released

2.6.19-1
edgy

released

2.6.19-1
feisty

released

2.6.19-1
gutsy

released

2.6.19-1
hardy

released

2.6.19-1
intrepid

released

2.6.19-1
jaunty

released

2.6.19-1
karmic

released

2.6.19-1
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 79%
0.01337
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
около 19 лет назад

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value.

debian
около 19 лет назад

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that ...

github
больше 3 лет назад

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value.

EPSS

Процентиль: 79%
0.01337
Низкий

7.5 High

CVSS2