CodeIgniter Cookie Encryption Security Weakness
BID:68010
Info
CodeIgniter Cookie Encryption Security Weakness
| Bugtraq ID: | 68010 |
| Class: | Design Error |
| CVE: |
CVE-2014-8686 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2014 12:00AM |
| Updated: | Mar 19 2015 07:35AM |
| Credit: | Robin Bailey |
| Vulnerable: |
EllisLab CodeIgniter 2.1 EllisLab CodeIgniter 2.0.3 EllisLab CodeIgniter 1.7.2 EllisLab CodeIgniter 1.7.1 EllisLab CodeIgniter 1.5.2 EllisLab CodeIgniter 1.0 |
| Not Vulnerable: | |
Exploit / POC
CodeIgniter Cookie Encryption Security Weakness
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
CodeIgniter Cookie Encryption Security Weakness
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].