CVE-2007-6546: Medium severity Runcms RunCMS vulnerability
Published Dec 28, 2007
·Updated
RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.
Affected Software
1 affected component
Runcms RunCMS<=1.6
Event History
Dec 28, 2007
CVE Published
12:46 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6546?
The severity of CVE-2007-6546 is considered important due to the risk of session hijacking.
2
How do I fix CVE-2007-6546?
To fix CVE-2007-6546, update to RunCMS version 1.6.1 or later, where the predictable session ID vulnerability is resolved.
3
What is the impact of CVE-2007-6546?
The impact of CVE-2007-6546 includes the potential for remote attackers to hijack user sessions.
4
Which versions of RunCMS are affected by CVE-2007-6546?
RunCMS versions before 1.6.1 are affected by CVE-2007-6546, particularly versions up to 1.6.
5
Who is at risk from CVE-2007-6546?
Users of RunCMS prior to version 1.6.1 are at risk from CVE-2007-6546 due to session management vulnerabilities.