|
|
| |
|
| |
request-tracker: session hijack vulnerability
| Package(s): | request-tracker |
CVE #(s): | CVE-2009-3585
|
| Created: | December 3, 2009 |
Updated: | December 11, 2009 |
| Description: |
From the Debian alert:
Mikal Gule discovered that request-tracker, an extensible trouble-ticket
tracking system, is prone to an attack, where an attacker with access
to the same domain can hijack a user's RT session. |
| Alerts: |
|
( Log in to post comments)
|
|
|