Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.800731
Category:General
Title:Novell eDirectory <= 8.8.5 Cookie Hijack Vulnerability
Summary:Novell eDirectory is prone to a session cookie hijack; vulnerability.
Description:Summary:
Novell eDirectory is prone to a session cookie hijack
vulnerability.

Vulnerability Insight:
The flaw is due to error in an 'DHOST' module when handling
DHOST web services. An attacker would wait until the real administrator logs in, then specify the
predicted cookie value to hijack their session.

Vulnerability Impact:
Successful exploitation will allow remote attackers to hijack
arbitrary sessions.

Affected Software/OS:
Novell eDirectory version 8.8.5 and prior.

Solution:
Apply the vendor provided patch.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-4655
http://www.metasploit.com/modules/auxiliary/admin/edirectory/edirectory_dhost_cookie
http://www.metasploit.com/redmine/projects/framework/repository/entry/modules/auxiliary/admin/edirectory/edirectory_dhost_cookie.rb
http://osvdb.org/60035
XForce ISS Database: edirectory-dhost-session-hijacking(56613)
https://exchange.xforce.ibmcloud.com/vulnerabilities/56613
CopyrightCopyright (C) 2010 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.