Vulnerability Description
SerendipityNZ (aka SimpleBoxes) Serene Bach 2.20R and earlier, and 3.00 beta023 and earlier 3.x versions, uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Serendipitynz | Serene Bach | <= 2.20r |
References
- http://jvn.jp/en/jp/JVN20689557/index.html
- http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000035.html
- http://secunia.com/advisories/35335Vendor Advisory
- http://serenebach.net/log/sb221R.htmlVendor Advisory
- http://www.securityfocus.com/bid/35254
- http://jvn.jp/en/jp/JVN20689557/index.html
- http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000035.html
- http://secunia.com/advisories/35335Vendor Advisory
- http://serenebach.net/log/sb221R.htmlVendor Advisory
- http://www.securityfocus.com/bid/35254
FAQ
What is CVE-2009-2165?
CVE-2009-2165 is a vulnerability with a CVSS score of 7.5 (HIGH). SerendipityNZ (aka SimpleBoxes) Serene Bach 2.20R and earlier, and 3.00 beta023 and earlier 3.x versions, uses a predictable session id, which makes it easier for remote attackers to hijack sessions v...
How severe is CVE-2009-2165?
CVE-2009-2165 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-2165?
Check the references section above for vendor advisories and patch information. Affected products include: Serendipitynz Serene Bach.