2.6
CVSSv2

CVE-2012-2731

Published: 27/06/2012 Updated: 29/08/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Ubercart AJAX Cart 6.x-2.x prior to 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote malicious users to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.

Vulnerable Product Search on Vulmon Subscribe to Product

richardo_ante ubercart_ajax_cart 6.x-2.0