CVE-2010-0756 Information

Description

Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.php/Comment/Main (2) index.php/Comment/Main/Home_Wiky or (3) index.php/Edit/Main.

Reference

http://packetstormsecurity.org/1002-exploits/wikyblog-rfishellxss.txt http://www.exploit-db.com/exploits/11560 http://www.securityfocus.com/bid/38386 https://exchange.xforce.ibmcloud.com/vulnerabilities/56594

Share on: