weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
                
            References
                    | Link | Resource | 
|---|---|
| http://secunia.com/advisories/36640 | Vendor Advisory | 
| http://webauth.stanford.edu/security/2009-09-10.html | Vendor Advisory | 
| http://secunia.com/advisories/36640 | Vendor Advisory | 
| http://webauth.stanford.edu/security/2009-09-10.html | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 01:06
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://secunia.com/advisories/36640 - Vendor Advisory | |
| References | () http://webauth.stanford.edu/security/2009-09-10.html - Vendor Advisory | 
Information
                Published : 2009-09-15 22:30
Updated : 2025-04-09 00:30
NVD link : CVE-2009-2945
Mitre link : CVE-2009-2945
CVE.ORG link : CVE-2009-2945
JSON object : View
Products Affected
                stanford
- webauth
 
CWE
                
                    
                        
                        CWE-255
                        
            Credentials Management Errors
