Vulnerabilities > Session Fixation

DATE CVE VULNERABILITY TITLE RISK
2018-11-04 CVE-2018-18926 Session Fixation vulnerability in Gitea
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.
network
low complexity
gitea CWE-384
critical
9.8
2018-11-04 CVE-2018-18925 Session Fixation vulnerability in Gogs
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go.
network
low complexity
gogs CWE-384
critical
9.8
2018-10-31 CVE-2018-13282 Session Fixation vulnerability in Synology Photo Station
Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
network
low complexity
synology CWE-384
6.3
2018-10-30 CVE-2018-16463 Session Fixation vulnerability in Nextcloud Server
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
network
high complexity
nextcloud CWE-384
3.1
2018-10-19 CVE-2018-18380 Session Fixation vulnerability in Bigtreecms Bigtree CMS
A Session Fixation issue was discovered in Bigtree before 4.2.24.
network
low complexity
bigtreecms CWE-384
5.4
2018-10-12 CVE-2018-17902 Session Fixation vulnerability in Yokogawa products
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions.
network
low complexity
yokogawa CWE-384
5.3
2018-09-28 CVE-2018-9082 Session Fixation vulnerability in Lenovo products
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one.
network
low complexity
lenovo CWE-384
8.8
2018-09-26 CVE-2018-8852 Session Fixation vulnerability in Philips E-Alert Firmware 2.1/R2.1
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
network
low complexity
philips CWE-384
8.8
2018-09-11 CVE-2018-1127 Session Fixation vulnerability in Redhat Gluster Storage
Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out.
network
high complexity
redhat CWE-384
8.1
2018-08-06 CVE-2017-1368 Session Fixation vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm CWE-384
6.5