CVE-2008-4122
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by int…
HIGH
Joomla CMS
Description
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Sévérité
7.5
Élevée · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | HIGH | 7.5 (v3.1) |
Produit et versions
- Produit
- Joomla CMS
- Corrigée dans
- Non précisée
- Publiée
- 19/12/2008
- Modifiée
- 16/06/2026
- CWE
- CWE-319
Versions concernées
- 1.5.8 – 1.5.8
Sources
- NVD CVE-2008-4122 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:27 UTC