The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain access to arbitrary user accounts, via HMAC timing attacks.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:15:20

Updated: 2022-10-03T16:15:20

Reserved: 2022-10-03T00:00:00


Link: CVE-2011-0910

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2011-02-08T21:00:01.447

Modified: 2020-06-04T12:58:52.123


Link: CVE-2011-0910

JSON object: View

cve-icon Redhat Information

No data.