CVE-2007-3050

Chameleon Cms < 3.0 - Authentication Bypass

Title source: rule

Description

Session fixation vulnerability in chameleon cms 3.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

Scores

EPSS 0.0126
EPSS Percentile 79.2%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

chameleon_cms/chameleon_cms < 3.0

Timeline

Published Jun 06, 2007
Tracked Since Feb 18, 2026