CVE-2011-1068
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Microsoft Windows Azure Software Development Kit (SDK) 1.3.x before 1.3.20121.1237, when Full IIS and a Web Role are used with an ASP.NET application, does not properly support the use of cookies for maintaining state, which allows remote attackers to obtain potentially sensitive information by reading an encrypted cookie and performing unspecified other steps.
Microsoft Windows Azure Software Development Kit (SDK) v1.3.x anterior a v1.3.20121.1237, cuando se usan Full IIS y un Web Role con una aplicación ASP.NET, no admite correctamente el uso de cookies para mantener el estado, que permite a atacantes remotos obtener información sensible mediante la lectura de una cookie cifrada y la realización de otras medidas no especificadas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-02-23 CVE Reserved
- 2011-02-23 CVE Published
- 2024-09-16 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://blogs.msdn.com/b/windowsazure/archive/2011/02/03/windows-azure-software-development-kit-sdk-refresh-released.aspx | 2011-04-21 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/43237 | 2011-04-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Windows Azure Sdk Search vendor "Microsoft" for product "Windows Azure Sdk" | 1.3 Search vendor "Microsoft" for product "Windows Azure Sdk" and version "1.3" | - |
Affected
|