Adobe ColdFusion CFID CFTOKEN Session Hijacking Vulnerability
BID:26429
Info
Adobe ColdFusion CFID CFTOKEN Session Hijacking Vulnerability
| Bugtraq ID: | 26429 |
| Class: | Design Error |
| CVE: |
CVE-2007-5905 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2007 12:00AM |
| Updated: | Nov 14 2007 05:44PM |
| Credit: | Michael Chabot is credited with the discovery of this issue. |
| Vulnerable: |
Adobe ColdFusion MX 7.00 Adobe ColdFusion 8.0 |
| Not Vulnerable: | |
Discussion
Adobe ColdFusion CFID CFTOKEN Session Hijacking Vulnerability
Adobe ColdFusion is prone to a vulnerability that allows attackers to hijack browser sessions.
Successful attacks will allow attackers to access potentially sensitive information and perform actions in the guise of legitimate users.
ColdFusion MX 7 and ColdFusion 8 are vulnerable; other versions may also be affected.
NOTE: This issue does not occur when using J2EE session management.
Adobe ColdFusion is prone to a vulnerability that allows attackers to hijack browser sessions.
Successful attacks will allow attackers to access potentially sensitive information and perform actions in the guise of legitimate users.
ColdFusion MX 7 and ColdFusion 8 are vulnerable; other versions may also be affected.
NOTE: This issue does not occur when using J2EE session management.
Exploit / POC
Adobe ColdFusion CFID CFTOKEN Session Hijacking Vulnerability
Attackers can use a browser to exploit this issue. The attacker may need to entice an unsuspecting user to follow a malicious URI.
Attackers can use a browser to exploit this issue. The attacker may need to entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Adobe ColdFusion CFID CFTOKEN Session Hijacking Vulnerability
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
References
Adobe ColdFusion CFID CFTOKEN Session Hijacking Vulnerability
References:
References: