Mantis Insecure Cookie Disclosure Weakness
BID:31344
Info
Mantis Insecure Cookie Disclosure Weakness
| Bugtraq ID: | 31344 |
| Class: | Design Error |
| CVE: |
CVE-2008-3102 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2008 12:00AM |
| Updated: | Apr 13 2015 09:56PM |
| Credit: | Hanno Boeck |
| Vulnerable: |
Mantis Mantis 1.1.2 Mantis Mantis 1.1.1 Mantis Mantis 1.1 Mantis Mantis 1.0.1 Mantis Mantis 1.0 Mantis Mantis 1.1.0a2 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Mantis Insecure Cookie Disclosure Weakness
Mantis is prone to a weakness that may allow an attacker to sniff network traffic and obtain cookie data.
An attacker may leverage this issue to obtain sensitive information, steal cookie-based authentication credentials, and carry out session-hijacking attacks; other attacks are also possible.
Mantis is prone to a weakness that may allow an attacker to sniff network traffic and obtain cookie data.
An attacker may leverage this issue to obtain sensitive information, steal cookie-based authentication credentials, and carry out session-hijacking attacks; other attacks are also possible.
Exploit / POC
Mantis Insecure Cookie Disclosure Weakness
An attacker can exploit the issue by using readily available network sniffers.
An attacker can exploit the issue by using readily available network sniffers.
Solution / Fix
Mantis Insecure Cookie Disclosure Weakness
Solution:
Fixes are available. Please see the references for more information.
Solution:
Fixes are available. Please see the references for more information.
References
Mantis Insecure Cookie Disclosure Weakness
References:
References:
- Mantis Homepage (Mantis)
- Mantis: Session hijacking vulnerability, CVE-2008-3102 (Hanno Boeck)