CVE-2010-5067 Information
Feb 14, 2021
cve
Description
Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user’s password which makes it easier for remote attackers to bypass timeout and logout actions and retain access for a long period of time by leveraging knowledge of a session cookie.
Reference
http://dmcdonald.net/vwar.txt http://seclists.org/fulldisclosure/2010/Aug/235
Share on: