Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-3102
Description:Mantis 1.1.x through 1.1.2 and 1.2.x through 1.2.0a2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
Test IDs: 1.3.6.1.4.1.25623.1.0.61744   1.3.6.1.4.1.25623.1.0.860629   1.3.6.1.4.1.25623.1.0.61915   1.3.6.1.4.1.25623.1.0.860396   1.3.6.1.4.1.25623.1.0.61749  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-3102
BugTraq ID: 31344
http://www.securityfocus.com/bid/31344
Bugtraq: 20080922 menalto gallery: Session hijacking vulnerability, CVE-2008-3102 (Google Search)
http://www.securityfocus.com/archive/1/496625/100/0/threaded
Bugtraq: 20080923 mantis CVE-2008-3102 (Re: menalto gallery: Session hijacking vulnerability, CVE-2008-3102) (Google Search)
http://www.securityfocus.com/archive/1/496684/100/0/threaded
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00504.html
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00648.html
http://www.gentoo.org/security/en/glsa/glsa-200812-07.xml
http://int21.de/cve/CVE-2008-3102-mantis.html
http://secunia.com/advisories/32243
http://secunia.com/advisories/32330
http://secunia.com/advisories/32975
http://securityreason.com/securityalert/4298
XForce ISS Database: mantis-cookie-session-hijacking(45395)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45395




© 1998-2025 E-Soft Inc. All rights reserved.