CVE-2012-2760
mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.
- Affected products
- Mod Auth Openidc
- Findingscience Mod Auth Openid
- ≤ 0.6, 0.1, 0.2, 0.2.1, 0.3, 0.4, 0.5
- Fix
- Available
- CVSS 2.0
- 2.1 LOW
- EPSS
- 1.0% (60th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2012-07-25
CVE-2012-2760 at NVD
5 known exploits for CVE-2012-2760
Proof-of-concept code and exploit modules indexed by Sploitus