CVE-2017-5831
03.03.2017, 15:59
Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.Enginsight
Vendor | Product | Version |
---|---|---|
revive-adserver | revive_adserver | 𝑥 ≤ 4.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References