Логотип exploitDog
bind:CVE-2020-15910
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15910

Количество 2

Количество 2

nvd логотип

CVE-2020-15910

больше 5 лет назад

SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible to influence the cookie with javascript. An attacker could send the user to a prepared webpage or by influencing JavaScript to the extract the JESSIONID. This could then be forwarded to the attacker.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-ppw4-rf73-v4fg

больше 3 лет назад

SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible to influence the cookie with javascript. An attacker could send the user to a prepared webpage or by influencing JavaScript to the extract the JESSIONID. This could then be forwarded to the attacker.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-15910

SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible to influence the cookie with javascript. An attacker could send the user to a prepared webpage or by influencing JavaScript to the extract the JESSIONID. This could then be forwarded to the attacker.

CVSS3: 4.7
0%
Низкий
больше 5 лет назад
github логотип
GHSA-ppw4-rf73-v4fg

SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible to influence the cookie with javascript. An attacker could send the user to a prepared webpage or by influencing JavaScript to the extract the JESSIONID. This could then be forwarded to the attacker.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу