« Volver al listado

CVE-2012-1840

Estado: ModificadaAlta (7.5)—

AjaXplorer v3.2.x antes de v3.2.5 y v4.0.x antes de v4.0.4 no realiza debidamente la autenticación de cookies, lo que permite a atacantes remotos iniciar una sesión aprovechandose de conocer el hash de una contraseña.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-1840",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-03-22T10:17:10.970",
  "references": [
    {
      "url": "http://ajaxplorer.info/ajaxplorer-4-0-4/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/504019",
      "tags": [
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/74305",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://ajaxplorer.info/ajaxplorer-4-0-4/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/504019",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/74305",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "AjaXplorer 3.2.x before 3.2.5 and 4.0.x before 4.0.4 does not properly perform cookie authentication, which allows remote attackers to obtain login access by leveraging knowledge of a password hash."
    },
    {
      "lang": "es",
      "value": "AjaXplorer v3.2.x antes de v3.2.5 y v4.0.x antes de v4.0.4 no realiza debidamente la autenticación de cookies, lo que permite a atacantes remotos iniciar una sesión aprovechandose de conocer el hash de una contraseña."
    }
  ],
  "lastModified": "2026-06-16T23:40:24.270",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AB14FF4-0CF0-4ACF-BA85-59196A259BAA"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA399184-3366-48E8-90F8-0BDF255DB2CA"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD6997D4-21C7-459F-8CB1-31E98C44BC91"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08354E81-1FF5-4CEF-8B5B-A3B3C514F03B"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:3.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC4FFE75-9BBE-4C9F-A7E5-350AC7701ECD"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "514ED912-D7FB-46CD-999C-4099D37DBF21"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:4.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9ACB6977-00FC-49D4-ACAA-E5BDF51E2533"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:4.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF45470B-525A-4716-B3C7-E75A33E89466"
            },
            {
              "criteria": "cpe:2.3:a:ajaxplorer:ajaxplorer:4.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0ABE4444-20F2-43D8-83BC-12839AA40AF3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}