Vulnerability Description
Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpfreechat | Phpfreechat | 1.0 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/31283Vendor Advisory
- http://www.phpfreechat.net/changelog/1.2Patch
- http://www.securityfocus.com/bid/30462Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44116
- http://secunia.com/advisories/31283Vendor Advisory
- http://www.phpfreechat.net/changelog/1.2Patch
- http://www.securityfocus.com/bid/30462Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44116
FAQ
What is CVE-2008-3428?
CVE-2008-3428 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid parameter.
How severe is CVE-2008-3428?
CVE-2008-3428 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3428?
Check the references section above for vendor advisories and patch information. Affected products include: Phpfreechat Phpfreechat.