Xataface Output Cache Session Hijacking Vulnerability
BID:47353
Info
Xataface Output Cache Session Hijacking Vulnerability
| Bugtraq ID: | 47353 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 13 2011 12:00AM |
| Updated: | Apr 13 2011 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Xataface Xataface 1.3rc1 Xataface Xataface 1.2 Xataface Xataface 1.1 Xataface Xataface 1.0 |
| Not Vulnerable: |
Xataface Xataface 1.3rc2 |
Discussion
Xataface Output Cache Session Hijacking Vulnerability
Xataface is prone to a vulnerability that allows attackers to a hijack a session.
Successful attacks will allow attackers to gain unauthorized access to the affected application.
Xataface versions 1.0 through 1.3rc1 are vulnerable.
Xataface is prone to a vulnerability that allows attackers to a hijack a session.
Successful attacks will allow attackers to gain unauthorized access to the affected application.
Xataface versions 1.0 through 1.3rc1 are vulnerable.
Exploit / POC
Xataface Output Cache Session Hijacking Vulnerability
Attackers can exploit this issue by conducting man-in-the-middle attacks.
Attackers can exploit this issue by conducting man-in-the-middle attacks.
Solution / Fix
Xataface Output Cache Session Hijacking Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Xataface Output Cache Session Hijacking Vulnerability
References:
References:
- Xataface - Homepage (Xataface)
- Xataface Release Notes (Xataface)