Vulnerability CVE-2010-3671


Published: 2019-11-05

Description:
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.

Type:

CWE-384

(Session Fixation)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.4/10
9.2/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
None
Affected software
Typo3 -> Typo3 

 References:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719
https://security-tracker.debian.org/tracker/CVE-2010-3671
https://typo3.org/security/advisory/typo3-sa-2010-012/#Broken_Authentication_and_Session_Management

Copyright 2024, cxsecurity.com

 

Back to Top