Description
Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www.adobe.com/support/security/bulletins/apsb09-12.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/57191
Scores
EPSS
0.0229
EPSS Percentile
81.0%
Details
CWE
CWE-287
Status
published
Products (9)
adobe/coldfusion
6.0 (5 CPE variants)
adobe/coldfusion
6.1 (5 CPE variants)
adobe/coldfusion
7.0 (5 CPE variants)
adobe/coldfusion
7.0.1
adobe/coldfusion
7.0.2
adobe/coldfusion
7.2 unknown
adobe/coldfusion
8.0
adobe/coldfusion
8.1
adobe/coldfusion
< 8.0.1
Published
Aug 18, 2009
Tracked Since
Feb 18, 2026