7.5
CVSSv2

CVE-2008-2970

Published: 02/07/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple session fixation vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and previous versions, allow remote malicious users to hijack web sessions by setting the PHPSESSID parameter to (1) index.php and (2) login.php in homepg/.

Vulnerable Product Search on Vulmon Subscribe to Product

yektaweb academic web tools

Exploits

########################## wwwBugReportir ####################################### # # AmnPardaz Security Research Team # # Title: Academic Web Tools CMS Multiple Vulnerabilities # Vendor: wwwyektawebcom # Vulnerable Version: 1428 and prior versions # Exploit: Available # Impact: Medium # Fix: N/A # Original Advisory: wwwbugreportir/ ...