Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-1944
HistoryApr 29, 2013 - 10:55 p.m.

Design/Logic Flaw

2013-04-2922:55:00
PRIOn knowledge base
www.prio-n.com
5

9.1 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.2%

The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.

References