5
CVSSv2

CVE-2013-4724

Published: 06/06/2014 Updated: 09/06/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote malicious users to obtain potentially sensitive information via script access to this cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

ddsn cm3 acora content management system 6.0.2\\/1a

ddsn cm3 acora content management system 5.5.7\\/12b

ddsn cm3 acora content management system 5.5.0\\/1b-p1

ddsn cm3 acora content management system 6.0.6\\/1a

Exploits

CM3 AcoraCMS versions 606/1a, 602/1a, 557/12b, and 550/1b-p1 suffer from cross site request forgery, cross site scripting, information disclosure, weak cookies, and URL redirection vulnerabilities ...