CVE Vulnerabilities

CVE-2009-2945

Published: Sep 15, 2009 | Modified: Sep 16, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

Affected Software

Name Vendor Start Version End Version
Webauth Stanford 3.5.5 (including) 3.5.5 (including)
Webauth Stanford 3.6.0 (including) 3.6.0 (including)
Webauth Stanford 3.6.1 (including) 3.6.1 (including)

References