Sphera HostingDirector Session ID Random Generator Weakness
BID:7904
Info
Sphera HostingDirector Session ID Random Generator Weakness
| Bugtraq ID: | 7904 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2003 12:00AM |
| Updated: | Jun 13 2003 12:00AM |
| Credit: | Discovery credited to "Lorenzo Hernandez Garcia-Hierro" <[email protected]>. |
| Vulnerable: |
Sphera HostingDirector 3.0 Sphera HostingDirector 2.0 Sphera HostingDirector 1.0 |
| Not Vulnerable: | |
Discussion
Sphera HostingDirector Session ID Random Generator Weakness
It has been reported that Sphera HostingDirector uses a weak method of generating session IDs. This problem may increase the possibility of an attacker brute-force guessing a valid session ID.
It has been reported that Sphera HostingDirector uses a weak method of generating session IDs. This problem may increase the possibility of an attacker brute-force guessing a valid session ID.
Exploit / POC
Sphera HostingDirector Session ID Random Generator Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sphera HostingDirector Session ID Random Generator Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.