CVE-2007-1966: Critical severity exv2 content management system vulnerability
Published Apr 11, 2007
·Updated
Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.
Affected Software
1 affected component
eXV2 Content Management System=2.0.4.3
Remediation
Patch Available
Event History
Apr 11, 2007
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1966?
CVE-2007-1966 is classified as a medium severity vulnerability.
2
How do I fix CVE-2007-1966?
To fix CVE-2007-1966, upgrade to eXV2 CMS version 2.0.4.4 or later.
3
What type of attack does CVE-2007-1966 enable?
CVE-2007-1966 enables remote attackers to perform session hijacking.
4
Which versions of eXV2 CMS are affected by CVE-2007-1966?
CVE-2007-1966 affects eXV2 CMS versions 2.0.4.3 and earlier.
5
What is the main issue caused by CVE-2007-1966?
The main issue caused by CVE-2007-1966 is the ability for attackers to set the PHPSESSID cookie and hijack user sessions.