4.3
CVSSv2

CVE-2009-3566

Published: 13/11/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

McAfee IntruShield Network Security Manager (NSM) prior to 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote malicious users to hijack a session by leveraging a cross-site scripting (XSS) vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

mcafee intrushield network security manager 5.1.7.73

mcafee intrushield network security manager 5.1.7.7

mcafee intrushield network security manager

Exploits

source: wwwsecurityfocuscom/bid/37004/info McAfee Network Security Manager is prone to an information-disclosure vulnerability because it fails to properly protect sensitive cookie data with the 'HTTPOnly' protection mechanism A successful exploit may allow attackers to steal cookie-based authentication credentials; information harveste ...
The McAfee Network Security Manager suffers from authentication bypass and session hijacking vulnerabilities ...