VulnerabilityModified
CVE-2007-2546
Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
MEDIUM 6.8EPSS 1.49%
Does this matter?
Lower severity and a low EPSS score (1.49%). Track it; it rarely justifies an emergency change on its own.
Description
Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.49% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- simple machines/simple machines forum
- Source
- cve@mitre.org
References
- http://osvdb.org/35705
- http://secunia.com/advisories/25139Vendor Advisory
- http://securityreason.com/securityalert/2676
- http://www.majorsecurity.de/index_2.php?major_rls=major_rls47
- http://www.securityfocus.com/archive/1/467748/100/0/threaded
- http://www.securityfocus.com/archive/1/471414/100/0/threaded
- http://www.securityfocus.com/bid/24482
- http://osvdb.org/35705
- http://secunia.com/advisories/25139Vendor Advisory
- http://securityreason.com/securityalert/2676
- http://www.majorsecurity.de/index_2.php?major_rls=major_rls47
- http://www.securityfocus.com/archive/1/467748/100/0/threaded
- http://www.securityfocus.com/archive/1/471414/100/0/threaded
- http://www.securityfocus.com/bid/24482
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.