Vulnerabilities > CVE-2006-1280 - Information Disclosure vulnerability in CGI::Session

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
sherzod-ruzmetov

Summary

CGI::Session 4.03-1 does not set proper permissions on temporary files created in (1) Driver::File and (2) Driver::db_file, which allows local users to obtain privileged information, such as session keys, by viewing the files.

Vulnerable Configurations

Part Description Count
Application
Sherzod_Ruzmetov
1