First published: Fri Dec 28 2007(Updated: )
RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runcms Runcms | <=1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-6546 is considered important due to the risk of session hijacking.
To fix CVE-2007-6546, update to RunCMS version 1.6.1 or later, where the predictable session ID vulnerability is resolved.
The impact of CVE-2007-6546 includes the potential for remote attackers to hijack user sessions.
RunCMS versions before 1.6.1 are affected by CVE-2007-6546, particularly versions up to 1.6.
Users of RunCMS prior to version 1.6.1 are at risk from CVE-2007-6546 due to session management vulnerabilities.