CVE-2008-6298

critical

Description

Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the "HTTP header rewrite function."

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/46516

http://www.vupen.com/english/advisories/2008/3105

http://www.securityfocus.com/bid/32247

http://secunia.com/advisories/32581

http://rocketeer.dip.jp/sanaki/free/free100.htm

http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000076.html

http://jvn.jp/en/jp/JVN67060882/index.html

Details

Source: Mitre, NVD

Published: 2009-02-26

Updated: 2026-04-23

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical

EPSS

EPSS: 0.0044