Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2017/02/02/3 | third party advisory mailing list |
https://www.revive-adserver.com/security/revive-sa-2017-001/ | patch vendor advisory |
http://www.securityfocus.com/bid/95875 | vdb entry |