5.8

CVE-2008-5809

futomi CGI Cafe Access Analyzer CGI Standard 4.0.1 and earlier and Access Analyzer CGI Professional 4.11.3 and earlier use a predictable session id, which makes it easier for remote attackers to hijack sessions, and obtain sensitive information about analysis results, via a modified id.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FutomiAccess Analyzer Cgi Editionstd Version <= 4.0.1
FutomiAccess Analyzer Cgi Version_nil_ Updatebeta1 Editionpro
FutomiAccess Analyzer Cgi Version_nil_ Updatebeta2 Editionpro
FutomiAccess Analyzer Cgi Version1.0 Editionpro
FutomiAccess Analyzer Cgi Version1.1 Editionpro
FutomiAccess Analyzer Cgi Version1.1 Editionstd
FutomiAccess Analyzer Cgi Version1.2 Editionpro
FutomiAccess Analyzer Cgi Version1.2 Editionstd
FutomiAccess Analyzer Cgi Version1.3 Editionpro
FutomiAccess Analyzer Cgi Version1.3 Editionstd
FutomiAccess Analyzer Cgi Version1.4 Editionpro
FutomiAccess Analyzer Cgi Version1.4 Editionstd
FutomiAccess Analyzer Cgi Version1.5 Editionpro
FutomiAccess Analyzer Cgi Version1.6 Editionpro
FutomiAccess Analyzer Cgi Version1.7 Editionpro
FutomiAccess Analyzer Cgi Version2.0 Editionpro
FutomiAccess Analyzer Cgi Version2.0 Editionstd
FutomiAccess Analyzer Cgi Version2.1 Editionpro
FutomiAccess Analyzer Cgi Version2.1 Editionstd
FutomiAccess Analyzer Cgi Version2.2 Editionpro
FutomiAccess Analyzer Cgi Version2.2 Editionstd
FutomiAccess Analyzer Cgi Version2.3 Editionpro
FutomiAccess Analyzer Cgi Version2.3 Editionstd
FutomiAccess Analyzer Cgi Version2.4 Editionpro
FutomiAccess Analyzer Cgi Version2.4 Editionstd
FutomiAccess Analyzer Cgi Version3.0 Editionpro
FutomiAccess Analyzer Cgi Version3.0 Editionstd
FutomiAccess Analyzer Cgi Version3.1 Editionpro
FutomiAccess Analyzer Cgi Version3.1 Editionstd
FutomiAccess Analyzer Cgi Version3.2 Editionpro
FutomiAccess Analyzer Cgi Version3.2 Editionstd
FutomiAccess Analyzer Cgi Version3.3 Editionpro
FutomiAccess Analyzer Cgi Version3.3 Editionstd
FutomiAccess Analyzer Cgi Version3.4 Editionpro
FutomiAccess Analyzer Cgi Version3.4 Editionstd
FutomiAccess Analyzer Cgi Version3.5 Editionpro
FutomiAccess Analyzer Cgi Version3.5 Editionstd
FutomiAccess Analyzer Cgi Version3.6 Editionstd
FutomiAccess Analyzer Cgi Version3.7 Editionstd
FutomiAccess Analyzer Cgi Version3.8 Editionstd
FutomiAccess Analyzer Cgi Version3.8.1 Editionstd
FutomiAccess Analyzer Cgi Version4.0 Editionpro
FutomiAccess Analyzer Cgi Version4.0.0 Editionstd
FutomiAccess Analyzer Cgi Version4.1 Editionpro
FutomiAccess Analyzer Cgi Version4.2 Editionpro
FutomiAccess Analyzer Cgi Version4.3 Editionpro
FutomiAccess Analyzer Cgi Version4.4 Editionpro
FutomiAccess Analyzer Cgi Version4.5 Editionpro
FutomiAccess Analyzer Cgi Version4.6 Editionpro
FutomiAccess Analyzer Cgi Version4.7 Editionpro
FutomiAccess Analyzer Cgi Version4.8 Editionpro
FutomiAccess Analyzer Cgi Version4.9 Editionpro
FutomiAccess Analyzer Cgi Version4.10 Editionpro
FutomiAccess Analyzer Cgi Version4.10.1 Editionpro
FutomiAccess Analyzer Cgi Version4.10.2 Editionpro
FutomiAccess Analyzer Cgi Version4.10.3 Editionpro
FutomiAccess Analyzer Cgi Version4.10.4 Editionpro
FutomiAccess Analyzer Cgi Version4.10.5 Editionpro
FutomiAccess Analyzer Cgi Version4.11.0 Editionpro
FutomiAccess Analyzer Cgi Version4.11.1 Editionpro
FutomiAccess Analyzer Cgi Version4.11.2 Editionpro
FutomiAccess Analyzer Cgi Version4.11.3 Editionpro
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.489
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.