CVE-2017-12965
CRITICALApache2Triad 1.5.4 - Info Disclosure
Title source: llmDescription
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
Exploits (1)
References (4)
Scores
CVSS v3
9.8
EPSS
0.2224
EPSS Percentile
95.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-384
Status
draft
Affected Products (1)
apache2triad/apache2triad
Timeline
Published
Aug 23, 2017
Tracked Since
Feb 18, 2026