ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it easier for remote attackers to (1) hijack a session or (2) cause a denial of service (session ID exhaustion) via a brute-force attack.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-05-14 10:30
Updated : 2018-10-10 12:37
NVD link : CVE-2009-1629
Mitre link : CVE-2009-1629
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
antony_lesuisse
- ajaxterm