Vulnerability Name: | CVE-2001-0922 (CCN-7620) | ||||||||
Assigned: | 2001-11-26 | ||||||||
Published: | 2001-11-26 | ||||||||
Updated: | 2017-12-19 | ||||||||
Summary: | ndcgi.exe in Netdynamics 4.x through 5.x, and possibly earlier versions, allows remote attackers to steal session IDs and hijack user sessions by reading the SPIDERSESSION and uniqueValue variables from the login field, then using those variables after the next user logs in. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Nov 26 2001 - 14:02:54 CST NMRC Advisory - NetDynamics Session ID is Reusable Source: MITRE Type: CNA CVE-2001-0922 Source: BUGTRAQ Type: UNKNOWN 20011126 NMRC Advisory - NetDynamics Session ID is Reusable Source: CCN Type: OSVDB ID: 13991 Netdynamics ndcgi.exe Previous User Session Replay Source: BID Type: Patch, Vendor Advisory 3583 Source: CCN Type: BID-3583 Sun NetDynamics Session ID Hijacking Vulnerability Source: CCN Type: Sun Microsystems Web site NetDynamics is the Power behind your portal Source: XF Type: UNKNOWN netdynamics-session-hijacking(7620) Source: XF Type: UNKNOWN netdynamics-session-hijacking(7620) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |