Security Advisory

CVE-2001-1534

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2005-07-14 04:00:00
Last updated 2024-09-17 03:27:53
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.