« Volver al listado

CVE-2008-3428

Estado: ModificadaMedia (6.5)—

Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid parameter.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-3428",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-07-31T22:41:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/31283",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.phpfreechat.net/changelog/1.2",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/30462",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44116",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/31283",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.phpfreechat.net/changelog/1.2",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/30462",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44116",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid parameter."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de fijación de sesión en  phpFreeChat 1.1, permite a usuarios remotos autenticados secuestrar sesiones web estableciendo el parámetro session_id para que sea igual al parámetro nickid."
    }
  ],
  "lastModified": "2026-06-16T22:55:48.577",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:phpfreechat:phpfreechat:1.0:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6204C447-457D-452E-A03E-89F1AE56D5A1"
            },
            {
              "criteria": "cpe:2.3:a:phpfreechat:phpfreechat:1.0:beta10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A338D15-82E9-4DE5-AF2A-F8D0D50237DE"
            },
            {
              "criteria": "cpe:2.3:a:phpfreechat:phpfreechat:1.0:beta11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5815AA94-0486-4273-ADFF-6BD672849742"
            },
            {
              "criteria": "cpe:2.3:a:phpfreechat:phpfreechat:1.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE81B0EF-6B46-46F0-B9B1-E78A145FA709"
            },
            {
              "criteria": "cpe:2.3:a:phpfreechat:phpfreechat:1.0:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7158BE17-6E19-42BC-8C97-9EDFD8FBC269"
            },
            {
              "criteria": "cpe:2.3:a:phpfreechat:phpfreechat:1.0:beta4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA6D6553-A28D-4DC6-91B8-F0F509853E88"
            },
            {
              "criteria": "cpe:2.3:a:phpfreechat:phpfreechat:1.0:beta5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "921349BA-B7F6-4E63-ADE6-5E6C7516FFF0"
            },
            {
              "criteria": "cpe:2.3:a:phpfreechat:phpfreechat:1.0:beta6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CD0845B-45FF-45FA-87E4-58332261379A"
            },
            {
              "criteria": "cpe:2.3:a:phpfreechat:phpfreechat:1.0:beta7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A21FAE77-B7A5-49DF-95BC-9B1AB13A63E2"
            },
            {
              "criteria": "cpe:2.3:a:phpfreechat:phpfreechat:1.0:beta8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2500C344-139C-43EF-B482-D3F3A65FE2DB"
            },
            {
              "criteria": "cpe:2.3:a:phpfreechat:phpfreechat:1.0:beta9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A6B4B10-2406-46C0-A834-C0582AD759EF"
            },
            {
              "criteria": "cpe:2.3:a:phpfreechat:phpfreechat:1.0:final:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "041AA248-D53A-4E2A-BC5C-13640624347B"
            },
            {
              "criteria": "cpe:2.3:a:phpfreechat:phpfreechat:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C85EE665-4438-43C8-9F19-F8212F023CCD"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}