Логотип exploitDog
bind:CVE-2007-6077
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2007-6077

Количество 4

Количество 4

ubuntu логотип

CVE-2007-6077

около 18 лет назад

The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an incomplete fix for CVE-2007-5380.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2007-6077

около 18 лет назад

The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an incomplete fix for CVE-2007-5380.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-6077

около 18 лет назад

The session fixation protection mechanism in cgi_process.rb in Rails 1 ...

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-p4c6-77gc-694x

около 8 лет назад

session fixation protection mechanism in cgi_process.rb in Rails

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2007-6077

The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an incomplete fix for CVE-2007-5380.

CVSS2: 6.8
4%
Низкий
около 18 лет назад
nvd логотип
CVE-2007-6077

The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an incomplete fix for CVE-2007-5380.

CVSS2: 6.8
4%
Низкий
около 18 лет назад
debian логотип
CVE-2007-6077

The session fixation protection mechanism in cgi_process.rb in Rails 1 ...

CVSS2: 6.8
4%
Низкий
около 18 лет назад
github логотип
GHSA-p4c6-77gc-694x

session fixation protection mechanism in cgi_process.rb in Rails

4%
Низкий
около 8 лет назад

Уязвимостей на страницу