PT-2014-3411 · Dle · Datalife Engine
Celsoft
·
Publicado
2014-06-02
·
Atualizado
2014-06-03
·
CVE-2013-7387
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
DataLife Engine (DLE) versions 9.7 and earlier
Description
A session fixation issue allows remote attackers to hijack web sessions via the PHPSESSID cookie.
Recommendations
For DataLife Engine (DLE) versions 9.7 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Datalife Engine