5
CVSSv2

CVE-2013-4725

Published: 06/06/2014 Updated: 09/06/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote malicious users to capture this cookie by intercepting its transmission within an http session.

Vulnerable Product Search on Vulmon Subscribe to Product

ddsn cm3 acora content management system 6.0.6\\/1a

ddsn cm3 acora content management system 5.5.7\\/12b

ddsn cm3 acora content management system 6.0.2\\/1a

ddsn cm3 acora content management system 5.5.0\\/1b-p1

Exploits

CM3 AcoraCMS versions 606/1a, 602/1a, 557/12b, and 550/1b-p1 suffer from cross site request forgery, cross site scripting, information disclosure, weak cookies, and URL redirection vulnerabilities ...