HP SiteScope Unspecified Session Fixation Vulnerability
BID:48916
Info
HP SiteScope Unspecified Session Fixation Vulnerability
| Bugtraq ID: | 48916 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2401 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2011 12:00AM |
| Updated: | Jul 28 2011 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
HP SiteScope 9.54 HP SiteScope 9.0 build 911 HP SiteScope 7.5 HP SiteScope 11.10 HP SiteScope 11.1 HP SiteScope 11.09 HP SiteScope 11.01 HP SiteScope 10.14 HP SiteScope 10.13 HP SiteScope 0 |
| Not Vulnerable: | |
Discussion
HP SiteScope Unspecified Session Fixation Vulnerability
HP SiteScope is prone to an unspecified session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
HP SiteScope versions 11.x, 10.x, 9.x, and prior are vulnerable.
HP SiteScope is prone to an unspecified session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
HP SiteScope versions 11.x, 10.x, 9.x, and prior are vulnerable.
Exploit / POC
HP SiteScope Unspecified Session Fixation Vulnerability
To exploit these issues an attacker entices an unsuspecting user into following a malicious URI.
To exploit these issues an attacker entices an unsuspecting user into following a malicious URI.
Solution / Fix
HP SiteScope Unspecified Session Fixation Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
HP SiteScope Unspecified Session Fixation Vulnerability
References:
References:
- HP Homepage (HP)
- HPSBMU02692 SSRT100581 (HP)