Vulnerability CVE-2008-4122


Published: 2008-12-19   Modified: 2009-01-29

Description:
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Joomla: Session hijacking vulnerability
Hanno Boeck
17.12.2008

Type:

CWE-310

(Cryptographic Issues)

Vendor: Joomla
Product: Joomla 
Version: 1.5.8;

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
http://www.securityfocus.com/archive/1/archive/1/499354/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/499295/100/0/threaded
http://securityreason.com/securityalert/4794
http://int21.de/cve/CVE-2008-4122-joomla.html

Related CVE
CVE-2017-14595
In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.
CVE-2017-14596
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
CVE-2015-5608
Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
CVE-2017-11364
The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.
CVE-2017-11612
In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
CVE-2017-9934
Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability.
CVE-2017-9933
Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.
CVE-2017-8917
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.

Copyright 2017, cxsecurity.com

 

Back to Top