Логотип exploitDog
bind:CVE-2022-25172
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-25172

Количество 2

Количество 2

nvd логотип

CVE-2022-25172

больше 3 лет назад

An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-pqgp-549c-xhq5

больше 3 лет назад

An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-25172

An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-pqgp-549c-xhq5

An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу