CENTER.HU groups
CENTER.HU address

User:

Guest

www.center.hu / Archive / Security news / november, 2004 / Multiple browsers non-secure channel cookies vulnerability 

Multiple browsers non-secure channel cookies vulnerability

Multiple browsers non-secure channel cookies vulnerability

Date Discovered: September 16, 2004
Date Published: November 3, 2004
Last Updated: November 3, 2004

Vulnerability Description

Vulnerability ID:          31645
Discovered by:            Paul Johnston
Exploitable Locally:     No
Exploitable Remotely: Yes
Impact:                        Remote attackers can compromise system security.
Root Cause:                 Software Vulnerability

Multiple browsers contain a vulnerability that can allow remote attackers to compromise system security. The vulnerability is due to cookies being improperly sent to non-secure and secure channels when the optional secure attribute is not implemented. Attackers can exploit the vulnerability using a carefully crafted cookie to compromise system security.

 

 

More information on CA Vulnerability Information Center
http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=31645

Computer Associates – the Trusted Source of Security Knowledge

 

Back




Copyright © CENTER.HU Ltd, 2000-2010. All rights reserved

sitemap | privacy policy |

copyrights | new pages |

terms of purchase | contact us


PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel