Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Octeth Oempro 3.5.5.1, and possibly other versions before 4, does not set the secure flag for the PHPSESSID cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Octeth Oempro cookie劫持漏洞
Vulnerability Description
oemPro是一款功能强大的邮件收发管理工具。 Octeth Oempro 3.5.5.1版本, 以及可能的4之前的版本,没有为一个https会话中的PHPSESSID cookie设置安全标签,这使远程攻击者易于通过在http会话中截取该cookie的传送来获得该cookie。
CVSS Information
N/A
Vulnerability Type
N/A