CVE

Id
44091  
CVE No.
CVE-2010-1507  
Status
Candidate  
Description
WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance"s image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key.  
Phase
Assigned (20100426)  
Votes
None (candidate not yet proposed)  
Comments