Session ID Exposure in Netegrity SiteMinder's SMSESSION Parameter
CVE-2003-1312 · MEDIUM Severity
AV:N/AC:M/AU:N/C:P/I:N/A:N
siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder places a session ID string in the value of the SMSESSION parameter in a URL, which might allow remote attackers to obtain the ID by sniffing, reading Referer logs, or other methods.
Learn more about our Web Application Penetration Testing UK.