Medium severity6.1NVD Advisory· Published Feb 6, 2020· Updated Jun 17, 2026
CVE-2014-10399
CVE-2014-10399
Description
The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:keplerproject:cgilua:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:keplerproject:cgilua:*:*:*:*:*:*:*:*range: >=5.0.0,<=5.0.1
- cpe:2.3:a:keplerproject:cgilua:5.2:alpha1:*:*:*:*:*:*
- cpe:2.3:a:keplerproject:cgilua:5.2:alpha2:*:*:*:*:*:*
- CGILua/session.lua librarydescription
Patches
Vulnerability mechanics
References
3- seclists.org/fulldisclosure/2014/Apr/318nvdMailing ListThird Party Advisory
- www.securityfocus.com/archive/1/531981/100/0/threadednvdThird Party AdvisoryVDB Entry
- www.syhunt.com/en/index.phpnvdThird Party Advisory
News mentions
0No linked articles in our index yet.