Unrated severityNVD Advisory· Published Jun 6, 2014· Updated Jun 16, 2026
CVE-2013-4725
CVE-2013-4725
Description
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
Affected products
5cpe:2.3:a:ddsn:cm3_acora_content_management_system:5.5.0\/1b-p1:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:ddsn:cm3_acora_content_management_system:5.5.0\/1b-p1:*:*:*:*:*:*:*
- cpe:2.3:a:ddsn:cm3_acora_content_management_system:5.5.7\/12b:*:*:*:*:*:*:*
- cpe:2.3:a:ddsn:cm3_acora_content_management_system:6.0.2\/1a:*:*:*:*:*:*:*
- cpe:2.3:a:ddsn:cm3_acora_content_management_system:6.0.6\/1a:*:*:*:*:*:*:*
- Range: 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1
Patches
Vulnerability mechanics
References
2- www.digitalsec.net/stuff/explt+advs/CM3.AcoraCMS.v6.txtnvdVendor Advisory
- osvdb.org/96664nvd
News mentions
0No linked articles in our index yet.