PT-2009-6476 · Transware · Transware Active! Mail
Kenichi Maehashi
·
Publicado
2009-12-17
·
Atualizado
2017-08-17
·
CVE-2009-4353
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
TransWARE Active! mail 2003 versions 2003.0139.0871 and earlier
Description
The issue allows remote attackers to hijack web sessions via vectors such as an email with an embedded URL, due to the failure to remove the session ID in a Referer URL.
Recommendations
For TransWARE Active! mail 2003 versions 2003.0139.0871 and earlier, consider disabling the use of Referer URLs until a patch is available to remove the session ID and prevent web session hijacking.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Transware Active! Mail