CVE-2001-1536

HIGH

audiogalaxy - Cleartext Storage of Sensitive Information in Cookies

Title source: llm
STIX 2.1

Description

Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.

References (3)

Core 3
Core References
Broken Link vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/7621.php
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3587

Scores

CVSS v3 7.5
EPSS 0.0135
EPSS Percentile 68.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-312
Status published
Products (1)
audiogalaxy/audiogalaxy
Published Dec 31, 2001
Tracked Since Feb 18, 2026