[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-0030Date: (C)2009-01-21   (M)2023-12-22


A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.5
Exploit Score: 8.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1021611
BID-33354
SECUNIA-33611
RHSA-2009:0057
SUSE-SR:2009:004
https://bugzilla.redhat.com/show_bug.cgi?id=480224
https://bugzilla.redhat.com/show_bug.cgi?id=480488
oval:org.mitre.oval:def:10366
squirrelmail-sessionid-session-hijacking(48115)

CWE    1
CWE-287
OVAL    7
oval:org.secpod.oval:def:200384
oval:org.secpod.oval:def:500548
oval:org.secpod.oval:def:200328
oval:org.secpod.oval:def:202682
...

© SecPod Technologies