Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS) vulnerability.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
McAfee网络安全管理器httpOnly会话劫持漏洞
Vulnerability Description
McAfee IntruShield Network Security Manager (NSM) 5.1.11.8.1版本之前的版本没有包含Set-Cookie页眉中对会话标识符的HTTPOnly标记,这会允许远程攻击者通过发动跨站脚本攻击,劫持会话。
CVSS Information
N/A
Vulnerability Type
N/A