6.8
CVSSv2

CVE-2008-6039

Published: 03/02/2009 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Session fixation vulnerability in BLUEPAGE CMS 2.5 and previous versions allows remote malicious users to hijack web sessions by setting the PHPSESSID parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

bluepage bluepage cms

bluepage bluepage cms 2.4.0

Exploits

source: wwwsecurityfocuscom/bid/31315/info BLUEPAGE CMS is prone to a session-fixation vulnerability Attackers can exploit this issue to hijack a user's session and gain unauthorized access to the affected application BLUEPAGE CMS 25 is vulnerable; other versions may also be affected wwwexamplecom/BluePageCMS/?PHPSESSID=15 ...