Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to hijack web sessions via unspecified vectors.
2011-08-09T22:55:00.807
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | novell | data_synchronizer | 1.0.0 | Yes |
Application | novell | data_synchronizer | 1.1.0 | Yes |
Application | novell | data_synchronizer | 1.1.1 | Yes |
Application | novell | data_synchronizer | 1.1.2 | Yes |
Application | novell | mobility_pack | 1.0 | Yes |
Application | novell | mobility_pack | 1.1 | Yes |
Application | novell | mobility_pack | 1.1.1 | Yes |
Application | novell | mobility_pack | 1.1.2 | Yes |