9.8
CVE-2014-8684
- EPSS 71.71%
- Veröffentlicht 19.09.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Codeigniter ≫ Codeigniter Version <= 2.2.6
Kohanaframework ≫ Kohana Version 3.2.3
Kohanaframework ≫ Kohana Version 3.3.0
Kohanaframework ≫ Kohana Version 3.3.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 71.71% | 0.994 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://packetstormsecurity.com/files/130609/Seagate-Business-NAS-Unauthenticated-Remote-Command-Execution.html
http://seclists.org/fulldisclosure/2014/May/54
https://github.com/kohana/core/pull/492
https://scott.arciszewski.me/research/full/php-framework-timing-attacks-object-injection