Информационная безопасность
[RU] switch to
English Version



CVECVE-2008-3170
СтатусCandidate
ОписаниеApple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cooking," a related issue to CVE-2004-0746, CVE-2004-0866, and CVE-2004-0867.
PhaseAssigned (14.07.2008)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3170
ReferencesAPPLE : APPLE-SA-2008-12-15
 BID : 30192
 CERT : TA08-350A
 CONFIRM : http://support.apple.com/kb/HT3338
 MISC : http://kuza55.blogspot.com/2008/07/some-random-saf...
 SECTRACK : 1020539
 SECUNIA : 31128
 VUPEN : ADV-2008-3444
 XF : safari-domains-session-hijacking(43839)
SecurityVulns:Многочисленные уязвимости в Apple Mac OS X

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server