← Back

CVE-2008-7296

nvd nist
Published: Aug 9, 2011Modified: Apr 29, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:P
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

Apple Safari cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

Affected (1)

Products: Apple: Safari
1 product
Safari
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

Related CWEs

Timeline

No history available yet.