Vulnerabilities > CVE-2006-1280 - Unspecified vulnerability in Sherzod Ruzmetov CGI Session

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

CGI::Session 4.03-1 does not set proper permissions on temporary files created in (1) Driver::File and (2) Driver::db_file, which allows local users to obtain privileged information, such as session keys, by viewing the files.

Vulnerable Configurations

Part Description Count
Application
Sherzod_Ruzmetov
1