2.6

CVE-2012-2731

Exploit
The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update alpha6
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update alpha7
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update alpha8
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta1
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta10
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta11
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta2
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta3
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta4
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta5
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta6
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta7
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta8
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update beta9
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update rc1
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update rc2
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update rc3
   Drupal ≫ Drupal Version -
Richardo Ante ≫ Ubercart Ajax Cart Version 6.x-2.0 Update rc4
   Drupal ≫ Drupal Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.17% 0.799
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www.openwall.com/lists/oss-security/2012/06/14/3
http://drupal.org/node/1619586
Patch
http://drupal.org/node/1633048
Patch
Vendor Advisory
http://drupalcode.org/project/uc_ajax_cart.git/commitdiff/b59cdd5
Exploit
http://www.securityfocus.com/bid/53999
https://exchange.xforce.ibmcloud.com/vulnerabilities/76332