McAfee Email and Web Security Appliance v5.6 – Session hijacking (and bypassing client-side session timeouts)
ID: 3b62e564-ba05-5316-a900-10c171c55f1b
STIX ID: report--3b62e564-ba05-5316-a900-10c171c55f1b
Feed Name: NCC Research
Threat Score
McAfee Email and Web Security Appliance v5.6 (v5.6 1741.115) contains a session hijacking vulnerability that allows an attacker who obtains a session token (for example via XSS) to bypass client-side timeouts and log in as an administrator; the report includes a proof-of-concept using intercepting proxies and documents discovery and a vendor fix released in March 2012.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
