CVE-2011-0910
Published Feb 8, 2011
Last updated 4 years ago
Overview
- Description
- The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain access to arbitrary user accounts, via HMAC timing attacks.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:vanillaforums:vanilla:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "38D5D119-9C36-4420-A8A1-98DB5EBDDBF8", "versionEndIncluding": "2.0.17.5" }, { "criteria": "cpe:2.3:a:vanillaforums:vanilla:2.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4AF565C5-1A0E-4C19-9354-FFBFA454B457" }, { "criteria": "cpe:2.3:a:vanillaforums:vanilla:2.0.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3B31A038-7B6A-43EB-B525-EF9CBB5F81C7" }, { "criteria": "cpe:2.3:a:vanillaforums:vanilla:2.0.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "57E4F91A-ED9A-4B98-80FF-6621237C285C" }, { "criteria": "cpe:2.3:a:vanillaforums:vanilla:2.0.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F3E2758-F9D3-46C5-9D32-FF284B91DA92" }, { "criteria": "cpe:2.3:a:vanillaforums:vanilla:2.0.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "27D49ACC-7D32-422F-916A-8B37512CA0FB" }, { "criteria": "cpe:2.3:a:vanillaforums:vanilla:2.0.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2F2BCC4D-DA3D-4EFE-A607-D03FCC7491E5" }, { "criteria": "cpe:2.3:a:vanillaforums:vanilla:2.0.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FC6FAD04-0DF7-4D32-8604-52A5C6C4C15E" }, { "criteria": "cpe:2.3:a:vanillaforums:vanilla:2.0.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF88B68F-D781-41D3-92DD-672C432BA763" }, { "criteria": "cpe:2.3:a:vanillaforums:vanilla:2.0.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "158E0328-3C61-4C95-B197-DE813DD0F810" }, { "criteria": "cpe:2.3:a:vanillaforums:vanilla:2.0.17.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "585F5145-1342-4EAD-A9F9-065A9694D227" }, { "criteria": "cpe:2.3:a:vanillaforums:vanilla:2.0.17.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "42800B41-380A-462A-8B21-9E014910D680" }, { "criteria": "cpe:2.3:a:vanillaforums:vanilla:2.0.17.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DB2B4009-09C3-49DD-AC10-D0D8F1CBE91A" }, { "criteria": "cpe:2.3:a:vanillaforums:vanilla:2.0.17.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "229FB439-E8BD-411B-B3B9-EF8A7EF20947" } ], "operator": "OR" } ] } ]