Description
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have been an opportunity for an attacker to steal an authenticated session.
Remediation
References
Related Vulnerabilities
PHP Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2017-11144)
WordPress Plugin WordPress Shortcodes-Shortcodes Ultimate Cross-Site Scripting (5.0.6)
Oracle Database Server CVE-2007-5509 Vulnerability (CVE-2007-5509)
WordPress Plugin Exit Popups & Onsite Retargeting by OptiMonk Cross-Site Scripting (1.2.5)