This script is Copyright (C) 2010-2015 Tenable Network Security, Inc.
The remote web server generates predictable session IDs.
The eDirectory DHost web server running on the remote host generates
predictable session IDs.
A remote attacker could exploit this by predicting the session ID of
a legitimately logged-in user, which could lead to the hijacking of
There is no known solution at this time.
Risk factor :
High / CVSS Base Score : 7.5
CVSS Temporal Score : 7.1
Public Exploit Available : true
Family: Web Servers
Nessus Plugin ID: 45109 (edir_dhost_predictable_ids.nasl)
Bugtraq ID: 38782
CVE ID: CVE-2009-4655
Upgrade to Nessus Professional today!
Start your free Nessus Cloud trial now!
Begin Free Trial
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.