First published: Thu Aug 05 2010(Updated: )
phpCAS before 1.1.2 allows remote authenticated users to hijack sessions via a query string containing a crafted ticket value.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apereo Phpcas | =0.5.0 | |
Apereo Phpcas | =0.4.13 | |
Apereo Phpcas | =1.1.0 | |
Apereo Phpcas | =0.4.20 | |
Apereo Phpcas | =0.4.6 | |
Apereo Phpcas | =0.4.14 | |
Apereo Phpcas | =0.4.16 | |
Apereo Phpcas | =0.4.19 | |
Apereo Phpcas | =0.6.0 | |
Apereo Phpcas | =0.3.2 | |
Apereo Phpcas | =0.4.5 | |
Apereo Phpcas | =0.4.2 | |
Apereo Phpcas | =0.4.8 | |
Apereo Phpcas | =0.4.17 | |
Apereo Phpcas | =0.4.4 | |
Apereo Phpcas | =0.4.22 | |
Apereo Phpcas | =0.4.10 | |
Apereo Phpcas | =0.4.11 | |
Apereo Phpcas | =0.4.3 | |
Apereo Phpcas | =0.3 | |
Apereo Phpcas | =0.5.1 | |
Apereo Phpcas | =1.0.0 | |
Apereo Phpcas | =0.3.1 | |
Apereo Phpcas | =0.2 | |
Apereo Phpcas | =0.4.1 | |
Apereo Phpcas | =0.4.21 | |
Apereo Phpcas | =1.0.1 | |
Apereo Phpcas | =0.4.12 | |
Apereo Phpcas | =0.4.18 | |
Apereo Phpcas | <=1.1.1 | |
Apereo Phpcas | =0.4.7 | |
Apereo Phpcas | =0.4.15 | |
Apereo Phpcas | =0.4 | |
Apereo Phpcas | =0.4.23 | |
Apereo Phpcas | =0.4.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2795 has a medium severity rating, making it a significant concern for applications using vulnerable versions of phpCAS.
To fix CVE-2010-2795, upgrade phpCAS to version 1.1.2 or later to mitigate session hijacking risks.
CVE-2010-2795 affects multiple versions of phpCAS, specifically versions prior to 1.1.2.
CVE-2010-2795 allows remote authenticated users to hijack sessions using crafted ticket values in a query string.
CVE-2010-2795 was first disclosed in September 2010.