PT-2009-1025 · Ajaxterm · Ajaxterm

Michael Greb

·

Publicado

2009-05-14

·

Atualizado

2018-10-10

·

CVE-2009-1629

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AjaxTerm versions 0.10 and earlier
Description The issue allows remote attackers to hijack a session or cause a denial of service due to session ID exhaustion via a brute-force attack. This is because session IDs are generated with predictable random numbers based on certain JavaScript functions.
Recommendations For AjaxTerm versions 0.10 and earlier, consider updating to a version that generates session IDs with truly random numbers to prevent session hijacking and denial of service attacks. As a temporary workaround, consider implementing additional session validation mechanisms to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03048
CVE-2009-1629
DSA-1994-1

Produtos afetados

Ajaxterm