Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rhm7-5gpj-qgx2

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.

IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.

EPSS

Процентиль: 95%
0.20307
Средний

Связанные уязвимости

nvd
больше 24 лет назад

IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.

EPSS

Процентиль: 95%
0.20307
Средний