7.5
CVSSv3

CVE-2016-4309

Published: 30/06/2016 Updated: 27/08/2020
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 765
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote malicious users to hijack web sessions via the PHPSESSID parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

getsymphony symphony 2.6.7

Exploits

[+] Credits: John Page aka hyp3rlinx [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/SYMPHONY-CMS-SESSION-FIXATIONtxt [+] ISR: APPARITIONSEC Vendor: ==================== wwwgetsymphonycom Product: ================== Symphony CMS v267 Download: wwwgetsymphonycom/download/ Symphony ...
Symphony CMS version 267 suffers from a session fixation vulnerability ...