Vulnerabilities (CVE)

Filtered by CWE-565
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-32725 1 Zabbix 2 Frontend, Zabbix Server 2023-12-22 N/A 8.8 HIGH
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
CVE-2021-33842 1 Circutor 2 Sge-plc1000, Sge-plc1000 Firmware 2023-11-23 7.7 HIGH 8.8 HIGH
Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be within the network where the device affected is located.
CVE-2022-30620 1 Cellinx 2 Cellinx Nvt - Ip Ptz Camera, Cellinx Nvt - Ip Ptz Camera Firmware 2023-08-08 N/A 8.8 HIGH
On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera.
CVE-2016-15002 1 Ideracorp 1 Webyog Monyog Ultimate 2022-06-15 6.5 MEDIUM 8.8 HIGH
A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. The manipulation of the argument HasServerEdit/IsAdmin leads to privilege escalation. It is possible to initiate the attack remotely.
CVE-2021-41819 6 Debian, Fedoraproject, Opensuse and 3 more 9 Debian Linux, Fedora, Factory and 6 more 2022-05-08 5.0 MEDIUM 7.5 HIGH
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
CVE-2022-28113 1 Fantec 2 Mwid25-ds, Mwid25-ds Firmware 2022-04-25 9.0 HIGH 7.2 HIGH
An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write files and reset the user passwords without having a valid session cookie.
CVE-2021-46388 1 Wago 2 750-8212 Pfc200 G2 2eth Rs, 750-8212 Pfc200 G2 2eth Rs Firmware 2022-02-28 9.0 HIGH 8.8 HIGH
WAGO 750-8212 PFC200 G2 2ETH RS Firmware version 03.05.10(17) is affected by a privilege escalation vulnerability. Improper handling of user cookies leads to escalating privileges to administrative account of the router.
CVE-2021-41263 1 Discourse 1 Rails Multisite 2021-11-19 6.0 MEDIUM 8.8 HIGH
rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails_multisite` alongside Rails' signed/encrypted cookies. Depending on how the application makes use of these cookies, it may be possible for an attacker to re-use cookies on different 'sites' within a multi-site Rails application. The issue has been patched in v4 of the `rails_multisite` gem. Note that this upgrade will invalidate all previous signed/encrypted cookies. The impact of this invalidation will vary based on the application architecture.
CVE-2018-19224 1 Laobancms 1 Laobancms 2020-08-24 5.0 MEDIUM 7.5 HIGH
An issue was discovered in LAOBANCMS 2.0. /admin/login.php allows spoofing of the id and guanliyuan cookies.
CVE-2012-5631 1 Freeipa 1 Freeipa 2019-12-09 6.8 MEDIUM 8.8 HIGH
ipa 3.0 does not properly check server identity before sending credential containing cookies
CVE-2019-17104 1 Centreon 1 Centreon Vm 2019-10-11 5.0 MEDIUM 7.5 HIGH
In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set.
CVE-2017-6896 1 Digisol 2 Dg-hr1400 Router, Dg-hr1400 Router Firmware 2019-10-03 6.5 MEDIUM 8.8 HIGH
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Base64-encoded session cookie value.