CVE-2001-1534

low

Description

mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.

References

http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00084.html

http://www.securityfocus.com/bid/3521

http://www.iss.net/security_center/static/7494.php

Details

Source: MITRE

Published: 2001-12-31

Updated: 2021-07-15

Type: CWE-384

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW