// For flags

CVE-2008-6009

SG Real Estate Portal 2.0 - Insecure Cookie Handling

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.

SG Real Estate Portal v2.0 permite a atacantes remotos evitar la autenticación y obtener acceso de administrador configurando la cookie Auth a 1.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-01-30 CVE Reserved
  • 2009-01-30 CVE Published
  • 2023-09-10 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sg Real Estate Portal
Search vendor "Sg Real Estate Portal"
Sg Real Estate Portal
Search vendor "Sg Real Estate Portal" for product "Sg Real Estate Portal"
2.0
Search vendor "Sg Real Estate Portal" for product "Sg Real Estate Portal" and version "2.0"
-
Affected