Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown
CVE-2022-30620
Disclosure Date: July 06, 2022 (last updated February 24, 2025)
On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera.
0
Attacker Value
Unknown
CVE-2016-15002
Disclosure Date: June 09, 2022 (last updated February 23, 2025)
A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. The manipulation of the argument HasServerEdit/IsAdmin leads to privilege escalation. It is possible to initiate the attack remotely.
0
Attacker Value
Unknown
CVE-2022-29248
Disclosure Date: May 25, 2022 (last updated February 23, 2025)
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the Set-Cookie header, allowing a malicious server to set cookies for unrelated domains. The cookie middleware is disabled by default, so most library consumers will not be affected by this issue. Only those who manually add the cookie middleware to the handler stack or construct the client with ['cookies' => true] are affected. Moreover, those who do not use the same Guzzle client to call multiple domains and have disabled redirect forwarding are not affected by this vulnerability. Guzzle versions 6.5.6 and 7.4.3 contain a patch for this issue. As a workaround, turn off the cookie middleware.
0
Attacker Value
Unknown
CVE-2022-22785
Disclosure Date: May 17, 2022 (last updated February 23, 2025)
The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.
0
Attacker Value
Unknown
CVE-2022-28113
Disclosure Date: April 15, 2022 (last updated February 23, 2025)
An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write files and reset the user passwords without having a valid session cookie.
0
Attacker Value
Unknown
CVE-2022-1148
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites
0
Attacker Value
Unknown
CVE-2021-41819
Disclosure Date: January 01, 2022 (last updated February 23, 2025)
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
0
Attacker Value
Unknown
CVE-2021-36338
Disclosure Date: December 19, 2021 (last updated February 23, 2025)
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.
0
Attacker Value
Unknown
CVE-2021-41263
Disclosure Date: November 15, 2021 (last updated February 23, 2025)
rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails_multisite` alongside Rails' signed/encrypted cookies. Depending on how the application makes use of these cookies, it may be possible for an attacker to re-use cookies on different 'sites' within a multi-site Rails application. The issue has been patched in v4 of the `rails_multisite` gem. Note that this upgrade will invalidate all previous signed/encrypted cookies. The impact of this invalidation will vary based on the application architecture.
0
Attacker Value
Unknown
CVE-2021-3818
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking
0