CVE Database · CVE-2008-3662
CVSS v3.1
N/A
EPSS
1.84%
Published
Sep 18, 2008
Modified
Jun 16, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
Weaknesses (CWE)
Affected Products (7)
References (20)