CVE-2008-6569
Cybozu Garoon 2.0.0-2.1.3 - Session Fixation via Login Page Session ID
Title source: llmDescription
Session fixation vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack web sessions via the session ID in the login page.
References (8)
Core 8
Core References
Vendor Advisory third-party-advisory
x_refsource_jvndb
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000034.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/29981
Vendor Advisory x_refsource_misc
http://www.lac.co.jp/info/advisory/98.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43427
Vendor Advisory x_refsource_confirm
http://cybozu.co.jp/products/dl/notice/detail/0021.html
Vendor Advisory third-party-advisory
x_refsource_jvn
http://jvn.jp/en/jp/JVN18700809/index.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/30871
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/46564
Scores
EPSS
0.0087
EPSS Percentile
75.5%
Details
CWE
CWE-287
Status
published
Products (11)
cybozu/garoon
2.0.0
cybozu/garoon
2.0.1
cybozu/garoon
2.0.2
cybozu/garoon
2.0.3
cybozu/garoon
2.0.4
cybozu/garoon
2.0.5
cybozu/garoon
2.0.6
cybozu/garoon
2.1.0
cybozu/garoon
2.1.1
cybozu/garoon
2.1.2
... and 1 more
Published
Mar 31, 2009
Tracked Since
Feb 18, 2026