Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-6059

Опубликовано: 05 фев. 2009
Источник: ubuntu
Приоритет: low
CVSS2: 5

Описание

xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

1.1.12-1ubuntu1
gutsy

ignored

end of life, was needed
hardy

not-affected

intrepid

not-affected

jaunty

not-affected

upstream

needs-triage

Показывать по

Ссылки на источники

5 Medium

CVSS2

Связанные уязвимости

redhat
около 17 лет назад

xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.

nvd
почти 17 лет назад

xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.

debian
почти 17 лет назад

xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not pro ...

github
больше 3 лет назад

xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.

5 Medium

CVSS2