CVE-2012-2760
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.0%
from disclosure to weapon0 days
Published on NVDJul 25
1st PoCMay 24
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/18917cve_referencepacketstormsecurity.org/files/112991/Mod_Auth_OpenID-Session-Stealing.htmlunverifiedcve_referencewww.exploit-db.com/exploits/18917unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/fulldisclosure/2012-05/0235.htmlhttp://packetstormsecurity.org/files/112991/Mod_Auth_OpenID-Session-Stealing.htmlhttp://secunia.com/advisories/49247https://exchange.xforce.ibmcloud.com/vulnerabilities/75813https://github.com/bmuller/mod_auth_openid/blob/master/ChangeLoghttps://github.com/bmuller/mod_auth_openid/pull/30http://www.exploit-db.com/exploits/18917http://www.mandriva.com/security/advisories?name=MDVSA-2012:114http://www.osvdb.org/82139http://www.securityfocus.com/bid/53661