Lucene search

K
prionPRIOn knowledge basePRION:CVE-2006-0411
HistoryJan 25, 2006 - 11:03 a.m.

Session fixation

2006-01-2511:03:00
PRIOn knowledge base
www.prio-n.com
1

7.6 High

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.3%

claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges.

CPENameOperatorVersion
clarolineeq1.7.2

7.6 High

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.3%

Related for PRION:CVE-2006-0411