VDB

CVE-2013-6166

CVE-2013-6166 PUBLISHED CVSS 6.800000190734863 MEDIUM

Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that forces a web application to set a malformed cookie within an HTTP response.

EPSS 1.86% · 78.2th percentile

Risk Scores

CVSS 2.0
6.800000190734863
EPSS Score
1.86%
78.2th percentile

Affected Products

VendorProductVersions
googlechrome0
n/an/an/a

Timeline

  • Apr 4, 2013 PoC Published
  • Feb 15, 2014 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 17, 2022 CVE Updated
  • May 21, 2022 EPSS Score
  • Jul 13, 2022 EPSS Score
  • Jul 30, 2022 EPSS Score
  • Oct 28, 2022 EPSS Score
  • Dec 20, 2022 EPSS Score
  • Feb 11, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›