Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-2047

Опубликовано: 14 мар. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vectors.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
lucid

DNE

precise

not-affected

quantal

ignored

end of life
saucy

ignored

end of life
trusty

not-affected

trusty/esm

DNE

trusty was not-affected
upstream

released

6.0.2
utopic

DNE

Показывать по

EPSS

Процентиль: 58%
0.00365
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vectors.

debian
почти 12 лет назад

Session fixation vulnerability in ownCloud before 6.0.2, when PHP is c ...

github
больше 3 лет назад

Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vectors.

EPSS

Процентиль: 58%
0.00365
Низкий

6.8 Medium

CVSS2