HIGH · 7.5

CVE-2005-4266

WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to per...

Vulnerability Description

WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Alt-NMdaemon8.1.3
Alt-NWorldclient8.1.3

References

FAQ

What is CVE-2005-4266?

CVE-2005-4266 is a vulnerability with a CVSS score of 7.5 (HIGH). WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to per...

How severe is CVE-2005-4266?

CVE-2005-4266 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-4266?

Check the references section above for vendor advisories and patch information. Affected products include: Alt-N Mdaemon, Alt-N Worldclient.