CVE-2008-4122

HIGH

Joomla! 1.5.8 - Cleartext Transmission of Sensitive Information via Session Cookie

Title source: llm
STIX 2.1

Description

Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

References (4)

Core 4
Core References
Broken Link, Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/499354/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4794
Broken Link, Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/499295/100/0/threaded
Third Party Advisory x_refsource_misc
http://int21.de/cve/CVE-2008-4122-joomla.html

Scores

CVSS v3 7.5
EPSS 0.0002
EPSS Percentile 5.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-319
Status published
Products (1)
joomla/joomla\! 1.5.8
Published Dec 19, 2008
Tracked Since Feb 18, 2026