CVE-2009-2165

SerendipityNZ (aka SimpleBoxes) Serene Bach 2.20R and earlier, and 3.00 beta023 and earlier 3.x versions, uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:serendipitynz:serene_bach:*:*:*:*:*:*:*:*
cpe:2.3:a:serendipitynz:serene_bach:1.18r:*:*:*:*:*:*:*
cpe:2.3:a:serendipitynz:serene_bach:1.19r:*:*:*:*:*:*:*
cpe:2.3:a:serendipitynz:serene_bach:2.05r:*:*:*:*:*:*:*
cpe:2.3:a:serendipitynz:serene_bach:2.08d:*:*:*:*:*:*:*
cpe:2.3:a:serendipitynz:serene_bach:2.09r:*:*:*:*:*:*:*
cpe:2.3:a:serendipitynz:serene_bach:3.00:beta023:*:*:*:*:*:*

History

No history.

Information

Published : 2009-06-22 20:30

Updated : 2023-12-10 10:51


NVD link : CVE-2009-2165

Mitre link : CVE-2009-2165

CVE.ORG link : CVE-2009-2165


JSON object : View

Products Affected

serendipitynz

  • serene_bach