CVE-2010-5067 Information

Description

Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user’s password which makes it easier for remote attackers to bypass timeout and logout actions and retain access for a long period of time by leveraging knowledge of a session cookie.

Reference

http://dmcdonald.net/vwar.txt http://seclists.org/fulldisclosure/2010/Aug/235

Share on: