Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Hastymail2 before RC 8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Hastymail2 cookie配置错误漏洞
Vulnerability Description
Hastymail是一个用PHP语言开发的IMAP/SMTP的Web 接口。 Hastymail2 RC 8之前版本没有正确为https会话中的会话cookie设置安全标记。远程攻击者更容易通过拦截带有http会话的cookie传输,截获该cookie。
CVSS Information
N/A
Vulnerability Type
N/A