CVE-2012-6494: XSS
Published Jan 25, 2020
·Updated
Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorized access.
Affected Software
1 affected component
Rapid7 Nexpose<5.5.4
Event History
Jan 25, 2020
CVE Published
via MITRE·06:41 PM
Data Sourced
via MITRE·06:41 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2012-6494.
2
What is the severity of CVE-2012-6494?
The severity of CVE-2012-6494 is medium.
3
What is the affected software?
The affected software is Rapid7 Nexpose versions up to exclusive version 5.5.4.
4
What is the description of CVE-2012-6494?
CVE-2012-6494 is a session hijacking vulnerability in Rapid7 Nexpose before 5.5.4, allowing remote attackers to capture a user's session and gain unauthorized access.
5
How can I fix CVE-2012-6494?
To fix CVE-2012-6494, you should update Rapid7 Nexpose to version 5.5.4 or later.