CVE-2018-5385
Summary
| CVE | CVE-2018-5385 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-24 15:29:00 UTC |
| Updated | 2023-11-07 02:58:00 UTC |
| Description | Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to bypassing the two factor authentication in some installations. This could lead to phishing attacks that can bypass the two factor authentication that is present in some installations. |
Risk And Classification
Problem Types: CWE-384
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Navarino Infinity VU#184077 Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Row, row, row your boat: Pwning ship’s VSAT for fun and profit. | medium.com | ||
| Navarino Infinity Blind SQL Injection / Session Fixation ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Row, row, row your boat: Pwning ship’s VSAT for fun and profit. | MISC | medium.com | Press/Media Coverage, Third Party Advisory |
| VU#184077 - Navarino Infinity web interface is affected by multiple vulnerabilities. | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.