CVE Vulnerabilities

CVE-2007-5380

Published: Oct 19, 2007 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to URL-based sessions.

Affected Software

Name Vendor Start Version End Version
Ruby_on_rails David_hansson * 1.2.3 (including)
Rails Ubuntu dapper *
Rails Ubuntu edgy *
Rails Ubuntu feisty *
Rails Ubuntu upstream *

References