Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: PCL-0001: Remote Vulnerability in HORDE MTA < 2.2.4 Aug 15 2003 03:35PM
Ricardo J. Ulisses Filho (ricardoj hotlink com br)
Hi,

I've made some tests here and could reproduce the same vulnerability behaviour
described in your advisory.
Reading about session handlers, in php.ini, there is an option called
"session.use_only_cookies", that, if set, avoids such sort of attack which
involves passing session ids in URLs.
U...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus