5

CVE-2014-2212

Exploit
The remember me feature in portal/scr_authentif.php in POSH (aka Posh portal or Portaneo) 3.0, 3.2.1, 3.3.0, and earlier stores the username and MD5 digest of the password in cleartext in a cookie, which allows attackers to obtain sensitive information by reading this cookie.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Posh ProjectPosh Version <= 3.3.0
Posh ProjectPosh Version1.0.1
Posh ProjectPosh Version1.1.0
Posh ProjectPosh Version1.2.0
Posh ProjectPosh Version1.3.0
Posh ProjectPosh Version1.3.2
Posh ProjectPosh Version1.4.2
Posh ProjectPosh Version1.5 Update-
Posh ProjectPosh Version1.5 Updatebeta
Posh ProjectPosh Version1.5 Updatebeta2
Posh ProjectPosh Version1.5 Updaterc
Posh ProjectPosh Version1.5.1
Posh ProjectPosh Version2.0 Update-
Posh ProjectPosh Version2.0 Updatebeta
Posh ProjectPosh Version2.0 Updatebeta2
Posh ProjectPosh Version2.0 Updatep1
Posh ProjectPosh Version2.0 Updaterc
Posh ProjectPosh Version2.1 Update-
Posh ProjectPosh Version2.1 Updateb
Posh ProjectPosh Version2.1 Updatep1
Posh ProjectPosh Version2.1 Updatep2
Posh ProjectPosh Version2.1 Updaterc
Posh ProjectPosh Version2.2 Update-
Posh ProjectPosh Version2.2 Updatebeta
Posh ProjectPosh Version2.2 Updaterc
Posh ProjectPosh Version2.2.1
Posh ProjectPosh Version2.2.3
Posh ProjectPosh Version2.3
Posh ProjectPosh Version3.0 Update-
Posh ProjectPosh Version3.0 Updatebeta
Posh ProjectPosh Version3.0.1
Posh ProjectPosh Version3.0.2
Posh ProjectPosh Version3.0.3
Posh ProjectPosh Version3.0.4
Posh ProjectPosh Version3.1.0
Posh ProjectPosh Version3.1.1
Posh ProjectPosh Version3.1.2
Posh ProjectPosh Version3.2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.495
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.