Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cx9-pwgj-7m88

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter.

Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter.

EPSS

Процентиль: 86%
0.02912
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 17 лет назад

Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter.

EPSS

Процентиль: 86%
0.02912
Низкий

Дефекты

CWE-287