CVE

Id
91128  
CVE No.
CVE-2016-4309  
Status
Candidate  
Description
Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter.  
Phase
Assigned (20160427)  
Votes
None (candidate not yet proposed)  
Comments