CVE-2017-5831
EUVD-2017-1490803.03.2017, 15:59
Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| revive-adserver | revive_adserver | 𝑥 ≤ 4.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References