Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-4689

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2008-4689
Last Modified 28 Jan 2009 01:39:50
Published 22 Oct 2008 02:00:01
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-4689

Summary

Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.

Vulnerable Systems

Application

  • Mantis 0.19.3

  • Mantis 0.19.4

  • Mantis 1.0.1

  • Mantis 1.0.2

  • Mantis 1.0.3

  • Mantis 1.0.4

  • Mantis 1.0.5

  • Mantis 1.0.6

  • Mantis 1.0.7

  • Mantis 1.0.8

  • Mantis 1.1.1

  • Mantis 1.1.2


References

XF - mantis-session-cookie-hijacking(46084)

MLIST - [oss-security] 20081020 Re: CVE request: mantisbt < 1.1.4: RCE

CONFIRM - http://www.mantisbt.org/bugs/view.php?id=9664

CONFIRM - http://www.mantisbt.org/bugs/file_download.php?file_id=1988&type=bug

CONFIRM - http://www.mantisbt.org/bugs/changelog_page.php

GENTOO - GLSA-200812-07

SECUNIA - 32975


Last Updated: 27 May 2016 10:48:35