Analysis of High-Performance Access CGI Session Identifier Session Hijacking Vulnerability
BID:32794
Info
Analysis of High-Performance Access CGI Session Identifier Session Hijacking Vulnerability
| Bugtraq ID: | 32794 |
| Class: | Design Error |
| CVE: |
CVE-2008-5809 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2008 12:00AM |
| Updated: | Jan 06 2009 03:52PM |
| Credit: | JVN |
| Vulnerable: |
Futomi's CGI Cafe Access Analyzer CGI 4.0.1 |
| Not Vulnerable: |
Futomi's CGI Cafe Access Analyzer CGI 4.0.2 |
Discussion
Analysis of High-Performance Access CGI Session Identifier Session Hijacking Vulnerability
Analysis of High-Performance Access CGI is prone to a session-hijacking vulnerability.
An attacker can exploit this issue to gain access to the affected application with the privileges of the hijacked user.
Analysis of High-Performance Access CGI 4.01 and prior are vulnerable.
Analysis of High-Performance Access CGI is prone to a session-hijacking vulnerability.
An attacker can exploit this issue to gain access to the affected application with the privileges of the hijacked user.
Analysis of High-Performance Access CGI 4.01 and prior are vulnerable.
Exploit / POC
Analysis of High-Performance Access CGI Session Identifier Session Hijacking Vulnerability
Attackers can use brute force techniques to exploit this issue.
Attackers can use brute force techniques to exploit this issue.
Solution / Fix
Analysis of High-Performance Access CGI Session Identifier Session Hijacking Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
Analysis of High-Performance Access CGI Session Identifier Session Hijacking Vulnerability
References:
References:
- Analysis of High Performance Access CGI Session Hijacking (JVN)
- Vendor Homepage (Futomi CGI Cafe)