BIGACE Web CMS Session Fixation Vulnerability
BID:56615
Info
BIGACE Web CMS Session Fixation Vulnerability
| Bugtraq ID: | 56615 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5173 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 21 2012 12:00AM |
| Updated: | Nov 21 2012 12:00AM |
| Credit: | Yuji Tonai |
| Vulnerable: |
BigACE BigACE 2.7.7 BigACE BigACE 2.7.6 BigACE BigACE 2.7.5 |
| Not Vulnerable: | |
Discussion
BIGACE Web CMS Session Fixation Vulnerability
BIGACE Web CMS is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
Versions prior to BIGACE Web CMS 2.7.8 are vulnerable.
BIGACE Web CMS is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
Versions prior to BIGACE Web CMS 2.7.8 are vulnerable.
Exploit / POC
BIGACE Web CMS Session Fixation Vulnerability
To exploit these issues an attacker entices an unsuspecting user into following a malicious URI.
To exploit these issues an attacker entices an unsuspecting user into following a malicious URI.
Solution / Fix
BIGACE Web CMS Session Fixation Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.