2.6

CVE-2012-2731

Exploit
The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Richardo AnteUbercart Ajax Cart Version6.x-2.0
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatealpha6
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatealpha7
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatealpha8
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatebeta1
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatebeta10
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatebeta11
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatebeta2
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatebeta3
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatebeta4
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatebeta5
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatebeta6
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatebeta7
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatebeta8
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updatebeta9
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updaterc1
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updaterc2
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updaterc3
   DrupalDrupal Version-
Richardo AnteUbercart Ajax Cart Version6.x-2.0 Updaterc4
   DrupalDrupal Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.695
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.