Логотип exploitDog
bind:CVE-2008-3661
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2008-3661

Количество 4

Количество 4

redhat логотип

CVE-2008-3661

почти 17 лет назад

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

EPSS: Низкий
nvd логотип

CVE-2008-3661

больше 16 лет назад

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-3661

больше 16 лет назад

Drupal, probably 5.10 and 6.4, does not set the secure flag for the se ...

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-q4hh-4qxq-c529

около 3 лет назад

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2008-3661

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

2%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3661

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

CVSS2: 5
2%
Низкий
больше 16 лет назад
debian логотип
CVE-2008-3661

Drupal, probably 5.10 and 6.4, does not set the secure flag for the se ...

CVSS2: 5
2%
Низкий
больше 16 лет назад
github логотип
GHSA-q4hh-4qxq-c529

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

2%
Низкий
около 3 лет назад

Уязвимостей на страницу