Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-1390
Description:The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.
Test IDs: 1.3.6.1.4.1.25623.1.0.60603   1.3.6.1.4.1.25623.1.0.60606  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-1390
BugTraq ID: 28316
http://www.securityfocus.com/bid/28316
Bugtraq: 20080318 AST-2008-005: HTTP Manager ID is predictable (Google Search)
http://www.securityfocus.com/archive/1/489819/100/0/threaded
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00438.html
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00514.html
http://www.securitytracker.com/id?1019679
http://secunia.com/advisories/29449
http://secunia.com/advisories/29470
http://securityreason.com/securityalert/3764
XForce ISS Database: asterisk-httpmanagerid-weak-security(41304)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41304




© 1998-2025 E-Soft Inc. All rights reserved.