SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-2437

cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.

MEDIUM 5.0EPSS 2.43%

Does this matter?

Lower severity and a low EPSS score (2.43%). Track it; it rarely justifies an emergency change on its own.

Description

cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
2.43% probability · 83th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
awcm-cms/ar web content manager
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.