9.8
CVSSv3

CVE-2017-12965

Published: 23/08/2017 Updated: 06/05/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Session fixation vulnerability in Apache2Triad 1.5.4 allows remote malicious users to hijack web sessions via the PHPSESSID parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache2triad apache2triad 1.5.4

Exploits

[+] Credits: John Page AKA hyp3rlinx [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/APACHE2TRIAD-SERVER-STACK-v154-MULTIPLE-CVEtxt [+] ISR: ApparitionSec Vendor: =============== apache2triadnet sourceforgenet/projects/apache2triad/ Product: =========== Apache2Triad v15 ...
Apache2Triad version 154 suffers from session fixation, cross site request forgery, and cross site scripting vulnerabilities ...