T-Mobile webConnect Manager sysauth Cookie Information Disclosure Weakness
BID:68065
Info
T-Mobile webConnect Manager sysauth Cookie Information Disclosure Weakness
| Bugtraq ID: | 68065 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2014 12:00AM |
| Updated: | Jun 14 2014 12:00AM |
| Credit: | Americas Testkitchen |
| Vulnerable: |
T-Mobile webConnect Manager 2.04.0030.0 |
| Not Vulnerable: | |
Exploit / POC
T-Mobile webConnect Manager sysauth Cookie Information Disclosure Weakness
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
References
T-Mobile webConnect Manager sysauth Cookie Information Disclosure Weakness
References:
References:
- Missing Secure Flag for sysauth Cookie #33 (areynold)
- Software-Updates schützen vor Sicherheitslücken (T-Mobile)
- T-Mobile Home Page (T-Mobile)