forums.cubecart.comConfirmation
http://forums.cubecart.com/topic/48427-cubecart-529-relased CVE-2014-2341
CubeCart 5.2.8 - Session Fixation
Record summary
CVE-2014-2341 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCubeCart 5.2.8 - Session FixationExploitDB exploitby absaneNot analyzed1 file
References
857856Third-party advisory
http://secunia.com/advisories/57856 32830exploit
http://www.exploit-db.com/exploits/32830 105784vdb entry
http://www.osvdb.org/105784 66805vdb entry
http://www.securityfocus.com/bid/66805 1030086vdb entry
http://www.securitytracker.com/id/1030086 cubecart-cve20142341-session-hijacking(92526)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/92526 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-2341