Devellion Limited CubeCart CVE-2014-2341 Session Fixation Vulnerability
BID:66805
Info
Devellion Limited CubeCart CVE-2014-2341 Session Fixation Vulnerability
| Bugtraq ID: | 66805 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2341 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2014 12:00AM |
| Updated: | Apr 10 2014 12:00AM |
| Credit: | James Sibley |
| Vulnerable: |
Devellion Limited CubeCart 5.2.8 |
| Not Vulnerable: |
Devellion Limited CubeCart 5.2.9 |
Discussion
Devellion Limited CubeCart CVE-2014-2341 Session Fixation Vulnerability
CubeCart is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
Versions prior to CubeCart 5.2.9 are vulnerable.
CubeCart is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
Versions prior to CubeCart 5.2.9 are vulnerable.