Session fixation vulnerability in Aipo and Aipo ASP 3.0.1.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
http://jvn.jp/jp/JVN%2370075625/index.html | third party advisory |
http://osvdb.org/41380 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36850 | vdb entry |
http://secunia.com/advisories/27004 | third party advisory patch vendor advisory |
http://www.securityfocus.com/bid/25843 | vdb entry |