Описание
Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vectors.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected] |
| lucid | DNE | |
| precise | not-affected | |
| quantal | ignored | end of life |
| saucy | ignored | end of life |
| trusty | not-affected | |
| trusty/esm | DNE | trusty was not-affected |
| upstream | released | 6.0.2 |
| utopic | DNE |
Показывать по
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vectors.
Session fixation vulnerability in ownCloud before 6.0.2, when PHP is c ...
Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vectors.
EPSS
6.8 Medium
CVSS2