Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to URL-based sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ruby_on_rails | David_hansson | * | 1.2.3 (including) |
Rails | Ubuntu | dapper | * |
Rails | Ubuntu | edgy | * |
Rails | Ubuntu | feisty | * |
Rails | Ubuntu | upstream | * |