VulnerabilityModified
CVE-2003-1481
CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.
MEDIUM 5.8EPSS 1.84%
Does this matter?
Lower severity and a low EPSS score (1.84%). Track it; it rarely justifies an emergency change on its own.
Description
CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 1.84% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- stalker/communigate pro
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/3290
- http://www.securityfocus.com/archive/1/320438
- http://www.securityfocus.com/bid/7501Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11932
- http://securityreason.com/securityalert/3290
- http://www.securityfocus.com/archive/1/320438
- http://www.securityfocus.com/bid/7501Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11932
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.