ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it easier for remote attackers to (1) hijack a session or (2) cause a denial of service (session ID exhaustion) via a brute-force attack.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2009-05-14 17:30
Updated : 2025-04-09 00:30
NVD link : CVE-2009-1629
Mitre link : CVE-2009-1629
CVE.ORG link : CVE-2009-1629
JSON object : View
Products Affected
antony_lesuisse
- ajaxterm
CWE
CWE-287
Improper Authentication