Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.807852
Category:Web application abuses
Title:Symphony CMS Session Fixation Vulnerability
Summary:Symphony CMS is prone to a session fixation vulnerability.
Description:Summary:
Symphony CMS is prone to a session fixation vulnerability.

Vulnerability Insight:
The flaw exists if the application is deployed using an insecure setup
with a php.ini 'session.use_only_cookies' not enabled and due to an error in application which does not
use or call 'session_regenerate_id' function upon successful user authentication.

Vulnerability Impact:
Successfully exploitation will allow remote
attacker to preset any users PHPSESSID session identifier and access the
affected application with the same level of access to that of the victim.

Affected Software/OS:
Symphony CMS version 2.6.7

Solution:
Configure your PHP via the php.ini to enable 'session.use_only_cookies'.

CVSS Score:
7.6

CVSS Vector:
AV:N/AC:H/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-4309
BugTraq ID: 91299
http://www.securityfocus.com/bid/91299
Bugtraq: 20160620 Symphony CMS v2.6.7 Session Fixation (Google Search)
http://www.securityfocus.com/archive/1/538714/100/0/threaded
https://www.exploit-db.com/exploits/39983/
http://hyp3rlinx.altervista.org/advisories/SYMPHONY-CMS-SESSION-FIXATION.txt
http://packetstormsecurity.com/files/137551/Symphony-CMS-2.6.7-Session-Fixation.html
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.