Vulnerabilities
Vulnerable Software
Haxx:  >> Libcurl  >> 7.21.0  Security Vulnerabilities
The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.
CVSS Score
5.0
EPSS Score
0.025
Published
2013-04-29
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
CVSS Score
4.3
EPSS Score
0.015
Published
2011-07-07


Contact Us

Shodan ® - All rights reserved