CVE-2008-3428

Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid parameter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
VendorProductVersion
phpfreechatphpfreechat
1.0:beta
phpfreechatphpfreechat
1.0:beta10
phpfreechatphpfreechat
1.0:beta11
phpfreechatphpfreechat
1.0:beta2
phpfreechatphpfreechat
1.0:beta3
phpfreechatphpfreechat
1.0:beta4
phpfreechatphpfreechat
1.0:beta5
phpfreechatphpfreechat
1.0:beta6
phpfreechatphpfreechat
1.0:beta7
phpfreechatphpfreechat
1.0:beta8
phpfreechatphpfreechat
1.0:beta9
phpfreechatphpfreechat
1.0:final
phpfreechatphpfreechat
1.1
𝑥
= Vulnerable software versions