Unspecified vulnerability in Default.aspx in Podium CMS allows remote attackers to have an unknown impact, possibly session fixation, via a META HTTP-EQUIV Set-cookie expression in the id parameter, related to "cookie manipulation." NOTE: this issue might be cross-site scripting (XSS).
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/468058/100/0/threaded | mailing list |
http://securityreason.com/securityalert/2664 | third party advisory |
http://www.securityfocus.com/archive/1/467823/100/0/threaded | mailing list |
http://osvdb.org/36182 | vdb entry |