CWE-598
86 CVEs • Abstraction: Variant
Use of GET Request Method With Sensitive Query Strings
The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.
CVEs (86)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Kunbus 1Pr100088 Modbus Gateway Firmware Jun 17, 2026 Apr 2, 2019 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) if the attacker is in an MITM position. |
Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker to impersonate a legitimate user and execute arbitrary...Show more |
1Belden 134Hirschmann M1 8mm Sc Hirschmann M1 8sfpHirschmann M1 8sm Sc+131 moreJun 17, 2026 Mar 6, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 An Information Exposure Through Query Strings in GET Request issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An information exposure through...Show more |
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or simi...Show more |
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name...Show more |
In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen. If the user enters credentials on this screen...Show more |