peter bassill · operator
$ cve CVE-2008-2970 JSON

CVE-2008-2970 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 83)

Patch early

A public exploit exists.

Description

Multiple session fixation vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to hijack web sessions by setting the PHPSESSID parameter to (1) index.php and (2) login.php in homepg/.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.36% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2008-07-02
Last modified2026-06-16

Affected (1)

VendorProduct
yektawebacademic web tools

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD