PT-2007-7378 · Runcms · Runcms

Alexandr Polyakov

+1

·

Publicado

2007-12-28

·

Atualizado

2018-10-15

·

CVE-2007-6546

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions RunCMS versions prior to 1.6.1
Description The issue makes it easier for remote attackers to hijack sessions. This is due to the use of a predictable session id, which can be modified by attackers.
Recommendations For versions prior to 1.6.1, update to version 1.6.1 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-6546

Produtos afetados

Runcms