CVE-2007-6470 Information
Feb 14, 2021
cve
Description
phpRPG 0.8 stores sensitive information under the web root with insufficient access control which allows remote attackers to read session ID values in files under tmp/ and then hijack sessions via PHPSESSID cookies.
Reference
http://marc.info/?l=bugtraq&m=119774326804168&w=2 http://secunia.com/advisories/27968 http://www.securityfocus.com/bid/26884
Share on: