2020-06-02 13:44:11
mitre
PUBLISHED
An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, because it is an authentication token.