Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4v8w-428c-cm63

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.php/Comment/Main, (2) index.php/Comment/Main/Home_Wiky, or (3) index.php/Edit/Main.

Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.php/Comment/Main, (2) index.php/Comment/Main/Home_Wiky, or (3) index.php/Edit/Main.

EPSS

Процентиль: 78%
0.01832
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 16 лет назад

Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.php/Comment/Main, (2) index.php/Comment/Main/Home_Wiky, or (3) index.php/Edit/Main.

EPSS

Процентиль: 78%
0.01832
Низкий

Дефекты

CWE-287