TROYANOSYVIRUS
Voltar para CVEs

CVE-2013-4725

N/A

Descricao

DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado6/6/2014
Ultima modificacao4/12/2025
Fontenvd
Avistamentos honeypot0

Produtos afetados

ddsn:cm3_acora_content_management_system

Fraquezas (CWE)

CWE-200

Referencias

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.