CVE-2008-2558
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD
Description
CRE Loaded 6.2.13.1 and earlier does not set the "Secure" attribute for cookies that are sent over HTTPS, which might allow remote attackers to sniff the cookies if they are sent over HTTP.
Affected (1)
Products: Cre Loaded: Cre Loaded
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.2.13.1 |
Related CWEs
References (4)
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
URL Repurposed
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.