Executive Summary

Informations
Name CVE-2012-2760 First vendor Publication 2012-07-25
Vendor Cve Last vendor Modification 2017-08-29

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:P/I:N/A:N)
Cvss Base Score 2.1 Attack Range Local
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2760

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-264 Permissions, Privileges, and Access Controls

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 6

ExploitDB Exploits

id Description
2012-05-24 Mod_Auth_OpenID Session Stealing Vulnerability

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/53661
CONFIRM https://github.com/bmuller/mod_auth_openid/blob/master/ChangeLog
EXPLOIT-DB http://www.exploit-db.com/exploits/18917
FULLDISC http://archives.neohapsis.com/archives/fulldisclosure/2012-05/0235.html
MANDRIVA http://www.mandriva.com/security/advisories?name=MDVSA-2012:114
MISC http://packetstormsecurity.org/files/112991/Mod_Auth_OpenID-Session-Stealing....
https://github.com/bmuller/mod_auth_openid/pull/30
OSVDB http://www.osvdb.org/82139
SECUNIA http://secunia.com/advisories/49247
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/75813

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
Date Informations
2021-05-04 12:20:02
  • Multiple Updates
2021-04-22 01:23:46
  • Multiple Updates
2020-05-23 01:48:51
  • Multiple Updates
2020-05-23 00:33:44
  • Multiple Updates
2017-08-29 09:23:50
  • Multiple Updates
2016-06-28 19:09:34
  • Multiple Updates
2016-04-26 21:52:12
  • Multiple Updates
2013-05-10 22:40:26
  • Multiple Updates
2013-04-05 13:18:46
  • Multiple Updates