PT-2007-6839 · Adobe · Coldfusion
Published
2007-11-15
·
Updated
2017-07-29
·
CVE-2007-5905
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Adobe ColdFusion versions 8 and MX 7
Description
The issue allows remote attackers to hijack sessions via unspecified vectors that trigger the establishment of a session to a ColdFusion application. This occurs when the
CFID or CFTOKEN cookies have empty values, possibly due to a session fixation issue.Recommendations
For Adobe ColdFusion versions 8 and MX 7, consider implementing session validation to ensure
CFID and CFTOKEN cookies are properly set and validated to prevent session hijacking.
At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coldfusion