Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-3662
Description:Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
Test IDs: 1.3.6.1.4.1.25623.1.0.62953   1.3.6.1.4.1.25623.1.0.62945  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-3662
BugTraq ID: 31231
http://www.securityfocus.com/bid/31231
Bugtraq: 20080918 menalto gallery: Session hijacking vulnerability, CVE-2008-3662 (Google Search)
http://www.securityfocus.com/archive/1/496509/100/0/threaded
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00794.html
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00832.html
http://seclists.org/fulldisclosure/2008/Sep/0379.html
http://security.gentoo.org/glsa/glsa-200811-02.xml
http://int21.de/cve/CVE-2008-3662-gallery.html
http://secunia.com/advisories/32662
http://secunia.com/advisories/33144




© 1998-2025 E-Soft Inc. All rights reserved.