PT-2014-3411 · Dle · Datalife Engine
Celsoft
·
Published
2014-06-02
·
Updated
2014-06-03
·
CVE-2013-7387
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
DataLife Engine (DLE) versions 9.7 and earlier
Description
A session fixation issue allows remote attackers to hijack web sessions via the PHPSESSID cookie.
Recommendations
For DataLife Engine (DLE) versions 9.7 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Datalife Engine