CVE-2009-2945
Severity CVSS v4.0:
Pending analysis
Type:
CWE-255
Credentials Management
Publication date:
15/09/2009
Last modified:
09/04/2025
Description
weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:stanford:webauth:3.5.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:stanford:webauth:3.6.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:stanford:webauth:3.6.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page