PT-2007-6839 · Adobe · Coldfusion
Publicado
2007-11-15
·
Atualizado
2017-07-29
·
CVE-2007-5905
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Adobe ColdFusion versions 8 and MX 7
Description
The issue allows remote attackers to hijack sessions via unspecified vectors that trigger the establishment of a session to a ColdFusion application. This occurs when the
CFID or CFTOKEN cookies have empty values, possibly due to a session fixation issue.Recommendations
For Adobe ColdFusion versions 8 and MX 7, consider implementing session validation to ensure
CFID and CFTOKEN cookies are properly set and validated to prevent session hijacking.
At the moment, there is no information about a newer version that contains a fix for this vulnerability. Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Coldfusion