CVE-2007-5905
CVE-2007-5905
Adobe ColdFusion 8 and MX 7 allows remote attackers to hijack sessions via unspecified vectors that trigger establishment of a session to a ColdFusion application in which the (1) CFID or (2) CFTOKEN cookies have empty values, possibly due to a session fixation vulnerability.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://osvdb.org/41478http://secunia.com/advisories/27644http://securitytracker.com/id?1018944https://exchange.xforce.ibmcloud.com/vulnerabilities/38446http://www.adobe.com/go/kb402805http://www.adobe.com/support/security/bulletins/apsb07-19.htmlhttp://www.securityfocus.com/bid/26429http://www.vupen.com/english/advisories/2007/3859