PT-2008-4013 · Cre Loaded · Cre Loaded

CVE-2008-2558

·

Publicado

2008-06-05

·

Atualizado

2024-02-14

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CRE Loaded versions 6.2.13.1 and earlier
Description The issue is related to the handling of cookies over HTTPS. Specifically, the software does not set the "Secure" attribute for cookies sent over HTTPS, which could allow remote attackers to sniff the cookies if they are sent over HTTP.
Recommendations For CRE Loaded versions 6.2.13.1 and earlier, ensure that the "Secure" attribute is set for cookies sent over HTTPS to prevent potential cookie sniffing attacks.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2558

Produtos afetados

Cre Loaded