>> CherryPy Cookie Session ID Handling Security Bypass Vulnerability
Title : CherryPy Cookie Session ID Handling Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2008-0039 CVE ID : CVE-2008-0252
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-01-07
Technical Description
A vulnerability has been identified in CherryPy, which could be exploited by attackers to bypass security restrictions. This issue is caused by an error in the "_get_file_path()" function that does not properly validate cookies when using file-based sessions, which could be exploited by attackers to gain unauthorized access to arbitrary files via a specially crafted session ID.