CVE-2012-2760
Published Jul 25, 2012
Last updated 7 years ago
Overview
- Description
- mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:findingscience:mod_auth_openid:*:*:*:*:*:apache:*:*", "vulnerable": true, "matchCriteriaId": "1685A1F9-5CFD-4324-85EB-EED26767E3EB", "versionEndIncluding": "0.6" }, { "criteria": "cpe:2.3:a:findingscience:mod_auth_openid:0.1:*:*:*:*:apache:*:*", "vulnerable": true, "matchCriteriaId": "F1DFE444-2072-4CBD-ADD3-62B31F3C5ACF" }, { "criteria": "cpe:2.3:a:findingscience:mod_auth_openid:0.2:*:*:*:*:apache:*:*", "vulnerable": true, "matchCriteriaId": "5BA74586-05D4-4E8D-AD57-249F4A76B3EC" }, { "criteria": "cpe:2.3:a:findingscience:mod_auth_openid:0.2.1:*:*:*:*:apache:*:*", "vulnerable": true, "matchCriteriaId": "2B8386D4-FE06-425F-833B-F014FF97AF18" }, { "criteria": "cpe:2.3:a:findingscience:mod_auth_openid:0.3:*:*:*:*:apache:*:*", "vulnerable": true, "matchCriteriaId": "78957F4D-07E7-4600-9F81-761774DFC3B9" }, { "criteria": "cpe:2.3:a:findingscience:mod_auth_openid:0.4:*:*:*:*:apache:*:*", "vulnerable": true, "matchCriteriaId": "79CE4540-AC19-433B-A19E-3D6FFC1DEB0B" }, { "criteria": "cpe:2.3:a:findingscience:mod_auth_openid:0.5:*:*:*:*:apache:*:*", "vulnerable": true, "matchCriteriaId": "8CF03C53-D086-4651-8B69-93CA15B73DD5" } ], "operator": "OR" } ] } ]