Unrated severityNVD Advisory· Published Jan 23, 2009· Updated Apr 23, 2026
CVE-2008-5964
CVE-2008-5964
Description
Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
Affected products
5cpe:2.3:a:impresscms:impresscms:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:impresscms:impresscms:*:*:*:*:*:*:*:*range: <=1.0.3
- cpe:2.3:a:impresscms:impresscms:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:impresscms:impresscms:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:impresscms:impresscms:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:impresscms:impresscms:1.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/32985nvdVendor Advisory
- wiki.impresscms.org/index.phpnvdVendor Advisory
- osvdb.org/50413nvd
- sourceforge.net/forum/forum.phpnvd
- www.securityfocus.com/archive/1/498734/100/0/threadednvd
- www.securityfocus.com/archive/1/498885/100/0/threadednvd
- www.securityfocus.com/bid/32495nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/46989nvd
News mentions
0No linked articles in our index yet.