CVE-2010-2795
CVE-2010-2795
phpCAS before 1.1.2 allows remote authenticated users to hijack sessions via a query string containing a crafted ticket value.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.fedoraproject.org/pipermail/package-announce/2010-August/046576.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-August/046584.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050415.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050428.htmlhttp://secunia.com/advisories/40845http://secunia.com/advisories/41240http://secunia.com/advisories/42149http://secunia.com/advisories/42184http://secunia.com/advisories/43427https://exchange.xforce.ibmcloud.com/vulnerabilities/60894https://forge.indepnet.net/projects/glpi/repository/revisions/12601https://issues.jasig.org/browse/PHPCAS-61