PT-2006-4892 · Netious · Netious Cms

Published

2006-08-09

·

Updated

2017-07-20

·

CVE-2006-4048

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Netious CMS version 0.4
Description The issue allows remote attackers to gain access to the administration section when originating from the same IP address as the administrator, due to session IDs being initialized based on the client IP address.
Recommendations For Netious CMS version 0.4, consider implementing a more secure session ID generation mechanism that does not rely solely on the client IP address, such as using a random or cryptographically secure token. As a temporary workaround, restrict access to the administration section to trusted IP addresses or networks until a more secure solution is implemented.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4048

Affected Products

Netious Cms