Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6470 (phpRPG)

BugsAlert Home > CVE-2007-6470 (phpRPG)
 
 

phpRPG 0.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read session ID values in files under tmp/, and then hijack sessions via PHPSESSID cookies.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6470

Learn more about CVE-2007-6470 (phpRPG)
 
Tags: cve-2007-6470 phprpg

Related Items

      Solving Privacy Issues in Ubuntu 8.10 Intrepid Ibex

      What best virus checker (to boot from CD)

      CVE-2008-2592 (advanced_replication_component, Oracle Database)

      CVE-2007-6203 (Apache)

      Trojan.Win32.ConnectionServices.e

      CVE-2008-1425 (Easy-Clanpage)

      CVE-2008-1414 (Multiple Time Sheets)

 

Pixel