CVE-2008-6298
Summary
| CVE | CVE-2008-6298 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-02-26 16:17:19 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the "HTTP header rewrite function." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rocketeer.dip | Sisapilocation | 1.0.1.3 | All | All | All |
| Application | Rocketeer.dip | Sisapilocation | 1.0.1.4 | All | All | All |
| Application | Rocketeer.dip | Sisapilocation | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVN#67060882 sISAPILocation vulnerability bypasses HTTP header rewrite function | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| sISAPILocation HTTP Header Rewrite Security Bypass - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| sISAPILocation HTTP Header Rewrite Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000076.html | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| rocketeer.dip.jp/sanaki/free/free100.htm | af854a3a-2127-422b-91ae-364da2661108 | rocketeer.dip.jp | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.