Security Advisory

CVE-2007-5905

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2007-11-15 20:00:00
Last updated 2024-08-07 15:47:00
Assigner mitre
State PUBLISHED

Description

Adobe ColdFusion 8 and MX 7 allows remote attackers to hijack sessions via unspecified vectors that trigger establishment of a session to a ColdFusion application in which the (1) CFID or (2) CFTOKEN cookies have empty values, possibly due to a session fixation vulnerability.