VDB
CVE-2012-2760
CVE-2012-2760
PUBLISHED
CVSS 2.0999999046325684 LOW
mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.
EPSS 0.37% · 59.3th percentile
Risk Scores
CVSS 2.0
2.0999999046325684
EPSS Score
0.37%
59.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| findingscience | mod_auth_openid | 0, 0.1, 0.3 |
| n/a | n/a | n/a |
Timeline
- May 24, 2012 PoC Published
- Jul 25, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
References
- http://packetstormsecurity.org/files/112991/Mod_Auth_OpenID-Session-Stealing.html url
- 20120522 session stealing in mod_auth_openid - CVE-2012-2760 mailing-list
- MDVSA-2012:114 vendor-advisory
- modauthopenid-database-info-disclosure(75813) vdb
- 18917 exploit
- https://github.com/bmuller/mod_auth_openid/pull/30 url
- https://github.com/bmuller/mod_auth_openid/blob/master/ChangeLog url
- 49247 third-party-advisory
- 82139 vdb
- 53661 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2012-2760 advisory