CVE-2017-12965
CRITICALApache2Triad 1.5.4 - Info Disclosure
Title source: llmDescription
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
Exploits (1)
References (4)
Scores
CVSS v3
9.8
EPSS
0.2224
EPSS Percentile
95.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-384
Status
published
Products (1)
apache2triad/apache2triad
1.5.4
Published
Aug 23, 2017
Tracked Since
Feb 18, 2026