CVE-2010-0554
Geopp Geo++ Gncaster < 1.4.0.7 - Authentication Bypass
Title source: ruleDescription
The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attackers to hijack web sessions or bypass authentication via a replay attack.
References (5)
Scores
EPSS
0.0017
EPSS Percentile
37.7%
Classification
CWE
CWE-287
Status
draft
Affected Products (2)
geopp/geo\+\+_gncaster
< 1.4.0.7
geopp/geo\+\+_gncaster
Timeline
Published
Feb 04, 2010
Tracked Since
Feb 18, 2026