CVE-2016-2304

MEDIUM

Ecava Integraxor < 4.2.4502 - Information Disclosure

Title source: rule

Description

Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

Scores

CVSS v3 4.3
EPSS 0.0034
EPSS Percentile 56.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200
Status draft

Affected Products (1)

ecava/integraxor < 4.2.4502

Timeline

Published Apr 22, 2016
Tracked Since Feb 18, 2026