CVE-2014-10400

MEDIUM

CGILua 5.0.x - Session Fixation via Predictable Session ID

Title source: llm
STIX 2.1

Description

The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.

References (3)

Core 3
Core References
Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2014/Apr/318
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/archive/1/531981/100/0/threaded

Scores

CVSS v3 6.1
EPSS 0.0125
EPSS Percentile 65.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-384
Status published
Products (2)
keplerproject/cgilua 5.2 alpha1 (2 CPE variants)
keplerproject/cgilua 5.0.0 - 5.0.1
Published Feb 06, 2020
Tracked Since Feb 18, 2026