« Volver al listado

CVE-2009-2945

Estado: ModificadaMedia (4.3)—

weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-2945",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-09-15T22:30:00.327",
  "references": [
    {
      "url": "http://secunia.com/advisories/36640",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://webauth.stanford.edu/security/2009-09-10.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/36640",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://webauth.stanford.edu/security/2009-09-10.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-255"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history."
    },
    {
      "lang": "es",
      "value": "weblogin/login.fcgi (alias el script de conexión WebLogin) en WebAuth de la Universidad de Stanford v3.5.5, v3.6.0 y v3.6.1 coloca contraseñas en en las URL en determinadas circunstancias que implique una conversión de una solicitud POST a una petición GET, lo cual permite a atacantes dependiendo del contexto descubrir contraseñas mediante la lectura de (1) registros de acceso al servidor web, (2) registros Referer del servidor web, o (3) el historial del navegador."
    }
  ],
  "lastModified": "2026-06-16T23:10:33.117",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:stanford:webauth:3.5.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97D7A1DC-4604-487F-8016-C3C0A27D1CDC"
            },
            {
              "criteria": "cpe:2.3:a:stanford:webauth:3.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C64D291D-898C-40E2-9E03-14EED5D7A6B0"
            },
            {
              "criteria": "cpe:2.3:a:stanford:webauth:3.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "464011F9-EA17-4000-92CB-CE303026D856"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}