>> Apache Tomcat Cookie Data Processing Remote Session Hijacking Vulnerability
Title : Apache Tomcat Cookie Data Processing Remote Session Hijacking Vulnerability VUPEN ID : VUPEN/ADV-2007-2902 CVE ID : CVE-2007-3382 - CVE-2007-3385
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-08-16
Technical Description
A vulnerability has been identified in Apache Tomcat, which could be exploited by remote attackers to gain knowledge of sensitive information. This issue is caused by an error when processing cookies that contain a single quote, which could potentially allow attackers to disclose session IDs and hijack a user's session.