René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

84 lines
2.3 KiB
JSON

{
"id": "CVE-2008-2558",
"sourceIdentifier": "cve@mitre.org",
"published": "2008-06-05T21:32:00.000",
"lastModified": "2017-08-08T01:31:09.107",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "CRE Loaded 6.2.13.1 and earlier does not set the \"Secure\" attribute for cookies that are sent over HTTPS, which might allow remote attackers to sniff the cookies if they are sent over HTTP."
},
{
"lang": "es",
"value": "CRE Loaded 6.2.13.1 y versiones anteriores no cumple el atributo \"Secure\" para cookies que son enviadas sobre HTTPS, lo que puede permitir a atacantes remotos analizar las cookies si son enviadas sobre HTTP."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cre_loaded:cre_loaded:*:*:*:*:*:*:*:*",
"versionEndIncluding": "6.2.13.1",
"matchCriteriaId": "241ECBCF-F797-490B-97F9-770796829B28"
}
]
}
]
}
],
"references": [
{
"url": "http://oscommerceuniversity.com/lounge/index.php?topic=255.0",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42889",
"source": "cve@mitre.org"
}
]
}