5
CVSSv2

CVE-2014-2212

Published: 01/04/2014 Updated: 02/04/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The remember me feature in portal/scr_authentif.php in POSH (aka Posh portal or Portaneo) 3.0, 3.2.1, 3.3.0, and previous versions stores the username and MD5 digest of the password in cleartext in a cookie, which allows malicious users to obtain sensitive information by reading this cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

posh project posh 3.0

posh project posh 2.3

posh project posh 2.2.1

posh project posh 2.2

posh project posh 2.1

posh project posh 2.2.3

posh project posh 3.0.1

posh project posh 3.0.3

posh project posh 3.2.1

posh project posh 3.0.4

posh project posh 2.0

posh project posh 3.1.0

posh project posh

posh project posh 1.5

posh project posh 1.3.0

posh project posh 1.1.0

posh project posh 1.5.1

posh project posh 1.4.2

posh project posh 1.3.2

posh project posh 3.1.1

posh project posh 3.0.2

posh project posh 3.1.2

posh project posh 1.2.0

posh project posh 1.0.1