VulnerabilityModified
CVE-2012-2731
The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a…
LOW 2.6EPSS 2.17%
Does this matter?
Lower severity and a low EPSS score (2.17%). Track it; it rarely justifies an emergency change on its own.
Description
The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 2.17% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- richardo ante/ubercart ajax cart
- Source
- secalert@redhat.com
References
- http://drupal.org/node/1619586Patch
- http://drupal.org/node/1633048Patch, Vendor Advisory
- http://drupalcode.org/project/uc_ajax_cart.git/commitdiff/b59cdd5Exploit
- http://www.openwall.com/lists/oss-security/2012/06/14/3
- http://www.securityfocus.com/bid/53999
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76332
- http://drupal.org/node/1619586Patch
- http://drupal.org/node/1633048Patch, Vendor Advisory
- http://drupalcode.org/project/uc_ajax_cart.git/commitdiff/b59cdd5Exploit
- http://www.openwall.com/lists/oss-security/2012/06/14/3
- http://www.securityfocus.com/bid/53999
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76332
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.