CVE-2011-2224
N/A
N/A
Summary
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://secunia.com/advisories/45527
- http://www.novell.com/support/viewContent.do?externalId=7009058
- http://www.securityfocus.com/bid/49069
References
- http://secunia.com/advisories/45527
- http://www.novell.com/support/viewContent.do?externalId=7009058
- http://www.securityfocus.com/bid/49069
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.