|
|
| |
|
| |
rt3: session hijack
| Package(s): | rt3 |
CVE #(s): | CVE-2009-4151
|
| Created: | December 11, 2009 |
Updated: | December 16, 2009 |
| Description: |
From the CVE entry:
Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows remote attackers to hijack web sessions by setting the session identifier via a manipulation that leverages "HTTP access to the RT server," a related issue to CVE-2009-3585. |
| Alerts: |
|
( Log in to post comments)
|
|
|