{"api_version":"1","generated_at":"2026-07-23T10:22:28+00:00","cve":"CVE-2008-6298","urls":{"html":"https://cve.report/CVE-2008-6298","api":"https://cve.report/api/cve/CVE-2008-6298.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-6298","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-6298"},"summary":{"title":"CVE-2008-6298","description":"Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the \"HTTP header rewrite function.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2009-02-26 16:17:19","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://jvn.jp/en/jp/JVN67060882/index.html","name":"http://jvn.jp/en/jp/JVN67060882/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVN#67060882 sISAPILocation vulnerability bypasses HTTP header rewrite function","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32581","name":"http://secunia.com/advisories/32581","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"sISAPILocation HTTP Header Rewrite Security Bypass - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/32247","name":"http://www.securityfocus.com/bid/32247","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"sISAPILocation HTTP Header Rewrite Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000076.html","name":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000076.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/3105","name":"http://www.vupen.com/english/advisories/2008/3105","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rocketeer.dip.jp/sanaki/free/free100.htm","name":"http://rocketeer.dip.jp/sanaki/free/free100.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46516","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46516","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-6298","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-6298","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"6298","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rocketeer.dip","cpe5":"sisapilocation","cpe6":"1.0.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"6298","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rocketeer.dip","cpe5":"sisapilocation","cpe6":"1.0.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"6298","vulnerable":"1","versionEndIncluding":"1.0.2.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rocketeer.dip","cpe5":"sisapilocation","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T11:27:35.675Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://rocketeer.dip.jp/sanaki/free/free100.htm"},{"name":"32247","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/32247"},{"name":"32581","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32581"},{"name":"sisapilocation-httpheaders-security-bypass(46516)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46516"},{"name":"JVNDB-2008-000076","tags":["third-party-advisory","x_refsource_JVNDB","x_transferred"],"url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000076.html"},{"name":"ADV-2008-3105","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/3105"},{"name":"JVN#67060882","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/en/jp/JVN67060882/index.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-11-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the \"HTTP header rewrite function.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://rocketeer.dip.jp/sanaki/free/free100.htm"},{"name":"32247","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/32247"},{"name":"32581","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32581"},{"name":"sisapilocation-httpheaders-security-bypass(46516)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46516"},{"name":"JVNDB-2008-000076","tags":["third-party-advisory","x_refsource_JVNDB"],"url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000076.html"},{"name":"ADV-2008-3105","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/3105"},{"name":"JVN#67060882","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/en/jp/JVN67060882/index.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-6298","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the \"HTTP header rewrite function.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://rocketeer.dip.jp/sanaki/free/free100.htm","refsource":"CONFIRM","url":"http://rocketeer.dip.jp/sanaki/free/free100.htm"},{"name":"32247","refsource":"BID","url":"http://www.securityfocus.com/bid/32247"},{"name":"32581","refsource":"SECUNIA","url":"http://secunia.com/advisories/32581"},{"name":"sisapilocation-httpheaders-security-bypass(46516)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46516"},{"name":"JVNDB-2008-000076","refsource":"JVNDB","url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000076.html"},{"name":"ADV-2008-3105","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/3105"},{"name":"JVN#67060882","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN67060882/index.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-6298","datePublished":"2009-02-26T16:00:00.000Z","dateReserved":"2009-02-26T00:00:00.000Z","dateUpdated":"2024-08-07T11:27:35.675Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-02-26 16:17:19","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rocketeer.dip:sisapilocation:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.2.0","matchCriteriaId":"5A760AC3-7A95-45E1-8A7F-21C2CFC32152"},{"vulnerable":true,"criteria":"cpe:2.3:a:rocketeer.dip:sisapilocation:1.0.1.3:*:*:*:*:*:*:*","matchCriteriaId":"C212DB21-91C1-472C-9615-14162317B2B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:rocketeer.dip:sisapilocation:1.0.1.4:*:*:*:*:*:*:*","matchCriteriaId":"79CA7010-827F-42DE-95AB-975AF8F80B3E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"6298","Ordinal":"1","Title":"CVE-2008-6298","CVE":"CVE-2008-6298","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"6298","Ordinal":"1","NoteData":"Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the \"HTTP header rewrite function.\"","Type":"Description","Title":"CVE-2008-6298"},{"CveYear":"2008","CveId":"6298","Ordinal":"2","NoteData":"2009-02-26","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"6298","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}