PT-2010-2492 · Wikyblog · Wikyblog

Indoushka

·

Publicado

2010-02-27

·

Atualizado

2017-08-17

·

CVE-2010-0756

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions WikyBlog version 1.7.3 rc2
Description The issue allows remote attackers to hijack web sessions. This can be achieved by setting the jsessionid parameter to specific API endpoints, such as "index.php/Comment/Main", "index.php/Comment/Main/Home Wiky", or "index.php/Edit/Main".
Recommendations For WikyBlog version 1.7.3 rc2, consider restricting access to the jsessionid parameter in the mentioned API endpoints as a temporary workaround until a patch is available. Avoid using the jsessionid parameter in the affected API endpoints until the issue is resolved.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-0756

Produtos afetados

Wikyblog