Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
      • Vulnerability archives
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
  • Research
Home > Products and services > InfoSec vulnerability disclosures > Predictable session identifiers in Crystal Reports

InfoSec vulnerability disclosures

Predictable session identifiers in Crystal Reports

ID: 00818
Ref: 546575
Date: 28 November 2006:11:46:01
Version: 1

Title: Predictable session identifiers in Crystal Reports
Abstract: The way in which the web interface for Crystal Reports stores a session identifier could allow an attacker to hijack an authenticated session.
Document link: Predictable session identifiers in Crystal Reports

  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |