CVE-2009-1629
14.05.2009, 17:30
ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it easier for remote attackers to (1) hijack a session or (2) cause a denial of service (session ID exhaustion) via a brute-force attack.Enginsight
Vendor | Product | Version |
---|---|---|
antony_lesuisse | ajaxterm | 𝑥 ≤ 0.10 |
antony_lesuisse | ajaxterm | 0.6 |
antony_lesuisse | ajaxterm | 0.7 |
antony_lesuisse | ajaxterm | 0.8 |
antony_lesuisse | ajaxterm | 0.9 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References