DataLife Engine Session Fixation Vulnerability
BID:57766
Info
DataLife Engine Session Fixation Vulnerability
| Bugtraq ID: | 57766 |
| Class: | Unknown |
| CVE: |
CVE-2013-7387 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2013 12:00AM |
| Updated: | Jun 30 2014 12:05AM |
| Credit: | Timur Yunusov of Positive Research Center |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
DataLife Engine Session Fixation Vulnerability
DataLife Engine is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
DataLife Engine 9.7 and prior are vulnerable.
DataLife Engine is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
DataLife Engine 9.7 and prior are vulnerable.
Exploit / POC
DataLife Engine Session Fixation Vulnerability
To exploit these issues an attacker entices an unsuspecting user into following a malicious URI.
To exploit these issues an attacker entices an unsuspecting user into following a malicious URI.
Solution / Fix
DataLife Engine Session Fixation Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
DataLife Engine Session Fixation Vulnerability
References:
References:
- DataLife Engine Homepage (Softnews Media Group)