Show plain JSON{"id": "CVE-2009-2945", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2009-09-15T22:30:00.327", "references": [{"url": "http://secunia.com/advisories/36640", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://webauth.stanford.edu/security/2009-09-10.html", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-255"}]}], "descriptions": [{"lang": "en", "value": "weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history."}, {"lang": "es", "value": "weblogin/login.fcgi (alias el script de conexi\u00f3n WebLogin) en WebAuth de la Universidad de Stanford v3.5.5, v3.6.0 y v3.6.1 coloca contrase\u00f1as en en las URL en determinadas circunstancias que implique una conversi\u00f3n de una solicitud POST a una petici\u00f3n GET, lo cual permite a atacantes dependiendo del contexto descubrir contrase\u00f1as mediante la lectura de (1) registros de acceso al servidor web, (2) registros Referer del servidor web, o (3) el historial del navegador."}], "lastModified": "2009-09-16T04:00:00.000", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:stanford:webauth:3.5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "97D7A1DC-4604-487F-8016-C3C0A27D1CDC"}, {"criteria": "cpe:2.3:a:stanford:webauth:3.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C64D291D-898C-40E2-9E03-14EED5D7A6B0"}, {"criteria": "cpe:2.3:a:stanford:webauth:3.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "464011F9-EA17-4000-92CB-CE303026D856"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}