First published: Fri Jul 06 2007(Updated: )
Session fixation vulnerability in Zen Cart 1.3.7 and earlier allows remote attackers to hijack web sessions by setting the Cookie parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zen Cart Zen Cart | <=1.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3597 is classified as a high-severity vulnerability due to its potential for session hijacking.
To fix CVE-2007-3597, it is recommended to upgrade to Zen Cart version later than 1.3.7.
CVE-2007-3597 affects Zen Cart versions 1.3.7 and earlier.
Yes, CVE-2007-3597 can allow remote attackers to gain unauthorized access to user sessions.
Session fixation refers to the attack method which allows an attacker to take control of a user's session by setting a predetermined session identifier.