Lucene search

K
cve[email protected]CVE-2012-2437
HistoryNov 26, 2012 - 12:45 p.m.

CVE-2012-2437

2012-11-2612:45:22
CWE-287
web.nvd.nist.gov
21
cve-2012-2437
cookie_gen.php
ar web content manager
awcm
authentication bypass

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.9 Medium

AI Score

Confidence

Low

0.057 Low

EPSS

Percentile

93.4%

cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.

Affected configurations

NVD
Node
awcm-cmsar_web_content_managerMatch2.2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.9 Medium

AI Score

Confidence

Low

0.057 Low

EPSS

Percentile

93.4%