DEBIAN-CVE-2009-2945

Source
https://security-tracker.debian.org/tracker/CVE-2009-2945
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-2945.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2009-2945
Upstream
Published
2009-09-15T22:30:00.327Z
Modified
2026-04-28T20:04:29.287200Z
Summary
[none]
Details

weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

References

Affected packages

Debian:11 / webauth

Package

Name
webauth
Purl
pkg:deb/debian/webauth?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.2-1

Ecosystem specific

{
    "urgency": "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-2945.json"