Back to search
CVE-2009-2945
Published: Sep 15, 2009
Modified: Sep 16, 2024
PUBLISHED
Description
weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://webauth.stanford.edu/security/2009-09-10.html
x_refsource_CONFIRM
36640
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now