CVE-2009-2165
22.06.2009, 20:30
SerendipityNZ (aka SimpleBoxes) Serene Bach 2.20R and earlier, and 3.00 beta023 and earlier 3.x versions, uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.Enginsight
Vendor | Product | Version |
---|---|---|
serendipitynz | serene_bach | 𝑥 ≤ 2.20r |
serendipitynz | serene_bach | 1.18r:r |
serendipitynz | serene_bach | 1.19r:r |
serendipitynz | serene_bach | 2.05r:r |
serendipitynz | serene_bach | 2.08d:d |
serendipitynz | serene_bach | 2.09r:r |
serendipitynz | serene_bach | 3.00:beta023 |
𝑥
= Vulnerable software versions
References