Описание
Invision Power Board 2.1.4 allows remote attackers to hijack sessions and possibly gain administrative privileges by obtaining the session ID from the s parameter, then replaying it in another request.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:invision_power_services:invision_power_board:2.1.4:*:*:*:*:*:*:*
EPSS
Процентиль: 74%
0.00849
Низкий
5.1 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Invision Power Board 2.1.4 allows remote attackers to hijack sessions and possibly gain administrative privileges by obtaining the session ID from the s parameter, then replaying it in another request.
EPSS
Процентиль: 74%
0.00849
Низкий
5.1 Medium
CVSS2
Дефекты
NVD-CWE-Other