PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remote attackers to obtain sensitive information by sniffing the network.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/437385 | US Government Resource |
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-04-15 16:13
Updated : 2014-04-16 07:40
NVD link : CVE-2014-2871
Mitre link : CVE-2014-2871
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
paperthin
- commonspot_content_server