7.5
CVSSv2

CVE-2008-4649

Published: 22/10/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote malicious users to hijack web sessions by setting the PHPSESSID parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

elxis elxis cms 2008.1

Exploits

source: wwwsecurityfocuscom/bid/31764/info Elxis CMS is prone to multiple cross-site scripting and session-fixation vulnerabilities because it fails to sufficiently sanitize user-supplied data The application is also prone to a session-fixation vulnerability An attacker may leverage these issues to execute arbitrary script code in th ...