5

CVE-2008-3662

Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GalleryGallery Version <= 2.2.5
GalleryGallery Version2.2.0
GalleryGallery Version2.2.1
GalleryGallery Version2.2.2
GalleryGallery Version2.2.3
GalleryGallery Version2.2.4
GalleryGallery Version <= 1.5.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.84% 0.762
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/32662
http://security.gentoo.org/glsa/glsa-200811-02.xml
http://gallery.menalto.com/gallery_1.5.9_released
Patch
http://gallery.menalto.com/gallery_2.2.6_released
Patch
http://int21.de/cve/CVE-2008-3662-gallery.html
http://seclists.org/fulldisclosure/2008/Sep/0379.html
http://secunia.com/advisories/33144
http://www.securityfocus.com/archive/1/496509/100/0/threaded
http://www.securityfocus.com/bid/31231
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00794.html
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00832.html