Vulnerabilities > CVE-2010-3892 - Unspecified vulnerability in IBM Omnifind

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote attackers to hijack web sessions by replaying a session ID (aka SID) value.

Vulnerable Configurations

Part Description Count
Application
Ibm
5

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/95687/ibmomnifind-xssescalate.txt
idPACKETSTORM:95687
last seen2016-12-05
published2010-11-10
reporterFatih Kilic
sourcehttps://packetstormsecurity.com/files/95687/IBM-OmniFind-Cross-Site-Scripting-Privilege-Escalation.html
titleIBM OmniFind Cross Site Scripting / Privilege Escalation