Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Adobe ColdFusion CFID CFTOKEN Session Hijacking Vulnerability

Adobe ColdFusion is prone to a vulnerability that allows attackers to hijack browser sessions.

Successful attacks will allow attackers to access potentially sensitive information and perform actions in the guise of legitimate users.

ColdFusion MX 7 and ColdFusion 8 are vulnerable; other versions may also be affected.

NOTE: This issue does not occur when using J2EE session management.







 

Privacy Statement
Copyright 2009, SecurityFocus