Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Claroline E-Learning Session Hijacking Vulnerability


Claroline e-Learning is prone to a session-hijacking vulnerability. This issue is due to the way the application creates cookie session data.

An attacker can exploit this issue to authenticate to the application as any valid logged-in user. This may facilitate a compromise of the application if an administrative account is used.







 

Privacy Statement
Copyright 2009, SecurityFocus