CVE-2009-2165

SerendipityNZ (aka SimpleBoxes) Serene Bach 2.20R and earlier, and 3.00 beta023 and earlier 3.x versions, uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
serendipitynzserene_bach
𝑥
≤ 2.20r
serendipitynzserene_bach
1.18r:r
serendipitynzserene_bach
1.19r:r
serendipitynzserene_bach
2.05r:r
serendipitynzserene_bach
2.08d:d
serendipitynzserene_bach
2.09r:r
serendipitynzserene_bach
3.00:beta023
𝑥
= Vulnerable software versions