{"api_version":"1","generated_at":"2026-07-23T08:05:47+00:00","cve":"CVE-2008-4122","urls":{"html":"https://cve.report/CVE-2008-4122","api":"https://cve.report/api/cve/CVE-2008-4122.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-4122","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-4122"},"summary":{"title":"CVE-2008-4122","description":"Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-12-19 17:30:02","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-319","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/499354/100/0/threaded","name":"http://www.securityfocus.com/archive/1/499354/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/499295/100/0/threaded","name":"http://www.securityfocus.com/archive/1/499295/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/4794","name":"http://securityreason.com/securityalert/4794","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Joomla: Session hijacking vulnerability - SecurityReason.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://int21.de/cve/CVE-2008-4122-joomla.html","name":"http://int21.de/cve/CVE-2008-4122-joomla.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Joomla: Session hijacking vulnerability, CVE-2008-4122","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-4122","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4122","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"4122","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"joomla","cpe5":"joomla\\!","cpe6":"1.5.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:08:33.955Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20081218 Re: Joomla: Session hijacking vulnerability, CVE-2008-4122","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/499354/100/0/threaded"},{"name":"4794","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4794"},{"name":"20081216 Joomla: Session hijacking vulnerability, CVE-2008-4122","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/499295/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://int21.de/cve/CVE-2008-4122-joomla.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-12-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20081218 Re: Joomla: Session hijacking vulnerability, CVE-2008-4122","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/499354/100/0/threaded"},{"name":"4794","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4794"},{"name":"20081216 Joomla: Session hijacking vulnerability, CVE-2008-4122","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/499295/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://int21.de/cve/CVE-2008-4122-joomla.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-4122","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20081218 Re: Joomla: Session hijacking vulnerability, CVE-2008-4122","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/499354/100/0/threaded"},{"name":"4794","refsource":"SREASON","url":"http://securityreason.com/securityalert/4794"},{"name":"20081216 Joomla: Session hijacking vulnerability, CVE-2008-4122","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/499295/100/0/threaded"},{"name":"http://int21.de/cve/CVE-2008-4122-joomla.html","refsource":"MISC","url":"http://int21.de/cve/CVE-2008-4122-joomla.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-4122","datePublished":"2008-12-19T17:00:00.000Z","dateReserved":"2008-09-18T00:00:00.000Z","dateUpdated":"2024-08-07T10:08:33.955Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-12-19 17:30:02","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-319","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:joomla:joomla\\!:1.5.8:*:*:*:*:*:*:*","matchCriteriaId":"466E5E84-4C69-49F2-83DA-FC86202DB7F4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"4122","Ordinal":"1","Title":"CVE-2008-4122","CVE":"CVE-2008-4122","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"4122","Ordinal":"1","NoteData":"Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.","Type":"Description","Title":"CVE-2008-4122"},{"CveYear":"2008","CveId":"4122","Ordinal":"2","NoteData":"2008-12-19","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"4122","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}