← Back

CVE-2014-2212

nvd nist
Published: Apr 1, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The remember me feature in portal/scr_authentif.php in POSH (aka Posh portal or Portaneo) 3.0, 3.2.1, 3.3.0, and earlier stores the username and MD5 digest of the password in cleartext in a cookie, which allows attackers to obtain sensitive information by reading this cookie.

Affected (38)

Products: Posh Project: Posh
1 product
Posh
Configuration A
38 vulnerable
Vulnerable SoftwareAffected Versions
Posh Project
Up to 3.3.0
Version 1.0.1
Version 1.1.0
Version 1.2.0
Version 1.3.0
Version 1.3.2
Version 1.4.2
Version 1.5.1
Version 1.5
Version 1.5 beta2
Version 1.5 beta
Version 1.5 rc
Version 2.0
Version 2.0 beta2
Version 2.0 beta
Version 2.0 p1
Version 2.0 rc
Version 2.1
Version 2.1 b
Version 2.1 p1
Version 2.1 p2
Version 2.1 rc
Version 2.2.1
Version 2.2.3
Version 2.2
Version 2.2 beta
Version 2.2 rc
Version 2.3
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0
Version 3.0 beta
Version 3.1.0
Version 3.1.1
Version 3.1.2
Version 3.2.1

Related CWEs

References (6)

Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.