2.6
CVE-2012-2731
- EPSS 2.17%
- Veröffentlicht 27.06.2012 00:55:05
- Zuletzt bearbeitet 16.06.2026 23:41:59
- Erkennungen
The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update alpha6
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update alpha7
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update alpha8
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta1
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta10
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta11
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta2
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta3
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta4
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta5
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta6
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta7
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta8
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta9
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update rc1
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update rc2
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update rc3
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update rc4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.17% | 0.799 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.openwall.com/lists/oss-security/2012/06/14/3
http://drupal.org/node/1619586
http://drupal.org/node/1633048
http://drupalcode.org/project/uc_ajax_cart.git/commitdiff/b59cdd5
http://www.securityfocus.com/bid/53999
https://exchange.xforce.ibmcloud.com/vulnerabilities/76332