CVE

Id
9183  
CVE No.
CVE-2004-0755  
Status
Candidate  
Description
The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.  
Phase
Assigned (20040728)  
Votes
None (candidate not yet proposed)  
Comments