Security Advisory

CVE-2017-6807

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-03-13 14:00:00
Last updated 2024-08-05 15:41:17
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site.