37178Third-party advisory
http://secunia.com/advisories/37178 CVE-2009-3566
McAfee Network Security Manager 5.1.7 - Information Disclosure
Record summary
CVE-2009-3566 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS) vulnerability.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMcAfee Network Security Manager 5.1.7 - Information DisclosureExploitDB exploitby Daniel KingNot analyzed1 file
References
101023172vdb entry
http://securitytracker.com/id?1023172 59912vdb entry
http://www.osvdb.org/59912 secureworks.com
http://www.secureworks.com/ctu/advisories/SWRX-2009-002 20091111 [SWRX-2009-002] McAfee Network Security Manager Authentication Bypass and Session Hijacking Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/507822/100/0/threaded 37004vdb entry
http://www.securityfocus.com/bid/37004 ADV-2009-3226vdb entry
http://www.vupen.com/english/advisories/2009/3226 nsm-httponly-session-hijacking(54251)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/54251 kc.mcafee.comConfirmation
https://kc.mcafee.com/corporate/index?page=content&id=SB10005 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-3566