![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2013-6167 |
Description: | Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that forces a web application to set a malformed cookie within an HTTP response. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.804502 1.3.6.1.4.1.25623.1.0.804501 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2013-6167 http://redmine.lighttpd.net/issues/2188 http://www.openwall.com/lists/oss-security/2013/04/03/10 http://seclists.org/oss-sec/2013/q4/117 http://seclists.org/oss-sec/2013/q4/121 |