6.5

CVE-2008-3428

Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhpfreechatPhpfreechat Version1.0 Updatebeta
PhpfreechatPhpfreechat Version1.0 Updatebeta10
PhpfreechatPhpfreechat Version1.0 Updatebeta11
PhpfreechatPhpfreechat Version1.0 Updatebeta2
PhpfreechatPhpfreechat Version1.0 Updatebeta3
PhpfreechatPhpfreechat Version1.0 Updatebeta4
PhpfreechatPhpfreechat Version1.0 Updatebeta5
PhpfreechatPhpfreechat Version1.0 Updatebeta6
PhpfreechatPhpfreechat Version1.0 Updatebeta7
PhpfreechatPhpfreechat Version1.0 Updatebeta8
PhpfreechatPhpfreechat Version1.0 Updatebeta9
PhpfreechatPhpfreechat Version1.0 Updatefinal
PhpfreechatPhpfreechat Version1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.592
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.