PT-2009-1025 · Ajaxterm · Ajaxterm

Michael Greb

·

Published

2009-05-14

·

Updated

2018-10-10

·

CVE-2009-1629

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AjaxTerm versions 0.10 and earlier
Description The issue allows remote attackers to hijack a session or cause a denial of service due to session ID exhaustion via a brute-force attack. This is because session IDs are generated with predictable random numbers based on certain JavaScript functions.
Recommendations For AjaxTerm versions 0.10 and earlier, consider updating to a version that generates session IDs with truly random numbers to prevent session hijacking and denial of service attacks. As a temporary workaround, consider implementing additional session validation mechanisms to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03048
CVE-2009-1629
DSA-1994-1

Affected Products

Ajaxterm