4.3
CVSSv2

CVE-2017-6807

Published: 13/03/2017 Updated: 15/03/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

mod_auth_mellon prior to 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

uninett mod auth mellon

Vendor Advisories

Cross-site session transfer vulnerability:It was found that mod_auth_mellon was vulnerable to a cross-site session transfer attack An attacker with access to one web site on a server could use the same session to get access to a different site running on the same server (CVE-2017-6807) ...