CVE-2008-3428
31.07.2008, 22:41
Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid parameter.Enginsight
| Vendor | Product | Version |
|---|---|---|
| phpfreechat | phpfreechat | 1.0:beta |
| phpfreechat | phpfreechat | 1.0:beta10 |
| phpfreechat | phpfreechat | 1.0:beta11 |
| phpfreechat | phpfreechat | 1.0:beta2 |
| phpfreechat | phpfreechat | 1.0:beta3 |
| phpfreechat | phpfreechat | 1.0:beta4 |
| phpfreechat | phpfreechat | 1.0:beta5 |
| phpfreechat | phpfreechat | 1.0:beta6 |
| phpfreechat | phpfreechat | 1.0:beta7 |
| phpfreechat | phpfreechat | 1.0:beta8 |
| phpfreechat | phpfreechat | 1.0:beta9 |
| phpfreechat | phpfreechat | 1.0:final |
| phpfreechat | phpfreechat | 1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References