Lucene search

K
nvd[email protected]NVD:CVE-2012-2437
HistoryNov 26, 2012 - 12:45 p.m.

CVE-2012-2437

2012-11-2612:45:22
CWE-287
web.nvd.nist.gov
3

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.037

Percentile

91.9%

cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.

Affected configurations

Nvd
Node
awcm-cmsar_web_content_managerMatch2.2
VendorProductVersionCPE
awcm-cmsar_web_content_manager2.2cpe:2.3:a:awcm-cms:ar_web_content_manager:2.2:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.037

Percentile

91.9%