Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-3662

Опубликовано: 18 сент. 2008
Источник: ubuntu
Приоритет: low
CVSS2: 5

Описание

Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

1.5.9-1.2ubuntu1
feisty

ignored

end of life, was needs-triage
gutsy

ignored

end of life, was needs-triage
hardy

ignored

end of life
intrepid

ignored

end of life, was needs-triage
jaunty

not-affected

1.5.9-1.2ubuntu1
karmic

not-affected

1.5.9-1.2ubuntu1
lucid

not-affected

1.5.9-1.2ubuntu1
maverick

not-affected

1.5.9-1.2ubuntu1

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

2.2.6-1
feisty

ignored

end of life, was needs-triage
gutsy

ignored

end of life, was needs-triage
hardy

ignored

end of life
intrepid

not-affected

2.2.6-1
jaunty

not-affected

2.2.6-1
karmic

not-affected

2.2.6-1
lucid

not-affected

2.2.6-1
maverick

not-affected

2.2.6-1

Показывать по

Ссылки на источники

5 Medium

CVSS2

Связанные уязвимости

redhat
около 17 лет назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

nvd
около 17 лет назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

debian
около 17 лет назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure fl ...

github
больше 3 лет назад

Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

5 Medium

CVSS2