CVE-2008-5964: Medium severity ImpressCMS ImpressCMS vulnerability
Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Social ImpressCMSto a version that resolves this vulnerability.Fixed in 1.1.1 RC1
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5964?
CVE-2008-5964 has a medium severity level, indicating a significant impact on security.
How do I fix CVE-2008-5964?
To fix CVE-2008-5964, upgrade ImpressCMS to version 1.1.1 RC1 or later.
What does CVE-2008-5964 allow an attacker to do?
CVE-2008-5964 allows an attacker to hijack web sessions through session fixation.
Which versions of ImpressCMS are affected by CVE-2008-5964?
ImpressCMS versions 1.0, 1.0.1, 1.0.2, 1.1, and up to 1.0.3 are affected by CVE-2008-5964.
What is session fixation in the context of CVE-2008-5964?
Session fixation in CVE-2008-5964 refers to the vulnerability that exploits the ability to set the PHPSESSID parameter to hijack sessions.