cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.
References
Configurations
Information
Published : 2009-07-08 08:30
Updated : 2017-08-16 18:30
NVD link : CVE-2009-2367
Mitre link : CVE-2009-2367
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
iomega
- storcenter_pro