5

CVE-2008-6298

Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the "HTTP header rewrite function."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rocketeer.DipSisapilocation Version <= 1.0.2.0
Rocketeer.DipSisapilocation Version1.0.1.3
Rocketeer.DipSisapilocation Version1.0.1.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.48% 0.705
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://jvn.jp/en/jp/JVN67060882/index.html
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000076.html
http://rocketeer.dip.jp/sanaki/free/free100.htm
Patch
Vendor Advisory
http://secunia.com/advisories/32581
Vendor Advisory
http://www.securityfocus.com/bid/32247
http://www.vupen.com/english/advisories/2008/3105
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/46516