CVE-2008-3428

phpFreeChat 1.1 - Session Fixation

Title source: llm

Description

Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid parameter.

Scores

EPSS 0.0042
EPSS Percentile 61.8%

Classification

CWE
CWE-287
Status draft

Affected Products (13)

phpfreechat/phpfreechat
phpfreechat/phpfreechat
phpfreechat/phpfreechat
phpfreechat/phpfreechat
phpfreechat/phpfreechat
phpfreechat/phpfreechat
phpfreechat/phpfreechat
phpfreechat/phpfreechat
phpfreechat/phpfreechat
phpfreechat/phpfreechat
phpfreechat/phpfreechat
phpfreechat/phpfreechat
phpfreechat/phpfreechat

Timeline

Published Jul 31, 2008
Tracked Since Feb 18, 2026