CherryPy Cookie Session Id Information Disclosure Vulnerability
BID:27181
Info
CherryPy Cookie Session Id Information Disclosure Vulnerability
| Bugtraq ID: | 27181 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-0252 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2007 12:00AM |
| Updated: | Apr 13 2015 09:23PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
rPath rPath Linux 1 Redhat Fedora 7 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 CherryPy CherryPy 3.0.2 CherryPy CherryPy 2.1.1 |
| Not Vulnerable: | |
Discussion
CherryPy Cookie Session Id Information Disclosure Vulnerability
CherryPy is prone to an information-disclosure vulnerability because it fails to properly validate user access rights before performing certain actions.
Exploiting this issue may allow an attacker to bypass certain security restrictions and obtain potentially sensitive information; other attacks are also possible.
This issue affects CherryPy 2.2.1 and 3.0.2.
CherryPy is prone to an information-disclosure vulnerability because it fails to properly validate user access rights before performing certain actions.
Exploiting this issue may allow an attacker to bypass certain security restrictions and obtain potentially sensitive information; other attacks are also possible.
This issue affects CherryPy 2.2.1 and 3.0.2.
Exploit / POC
CherryPy Cookie Session Id Information Disclosure Vulnerability
Attackers can use standard tools to exploit this issue.
Attackers can use standard tools to exploit this issue.
Solution / Fix
References
CherryPy Cookie Session Id Information Disclosure Vulnerability
References:
References: