Vulnerabilities > CVE-2007-3978 - Credentials Management vulnerability in Bwired

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
bwired
CWE-255
exploit available

Summary

Session fixation vulnerability in bwired allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

Vulnerable Configurations

Part Description Count
Application
Bwired
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionbwired (index.php newsID) Remote SQL Injection Vulnerability. CVE-2007-3976,CVE-2007-3977,CVE-2007-3978. Webapps exploit for php platform
fileexploits/php/webapps/4213.txt
idEDB-ID:4213
last seen2016-01-31
modified2007-07-22
platformphp
port
published2007-07-22
reporterg00ns
sourcehttps://www.exploit-db.com/download/4213/
titlebwired index.php newsID Remote SQL Injection Vulnerability
typewebapps