CVE-2009-4353
Last modified
CVE-2009-4353 is a vulnerability of currently unknown severity. The Mobile Edition of TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0911, does not remove the session ID in a Referer URL, which allows remote attackers to hijack web sessions via vectors such as an email with an embedded URL.. EPSS estimates a 1.08% chance of exploitation in the next 30 days.
Description
The Mobile Edition of TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2003.0139.0911, does not remove the session ID in a Referer URL, which allows remote attackers to hijack web sessions via vectors such as an email with an embedded URL.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Transware | Active\! Mail | <= 2003 |
References
- http://secunia.com/advisories/37602Vendor Advisory
- http://secunia.com/advisories/37602Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4353?
How severe is CVE-2009-4353?
How do I fix CVE-2009-4353?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-4347Cross-site scripting (XSS) vulnerability in daloradius-users…
- CVE-2009-4348Cross-site scripting (XSS) vulnerability in index.php in Har…
- CVE-2009-4349Cross-site request forgery (CSRF) vulnerability in administr…
- CVE-2009-4350SQL injection vulnerability in index.php in Arctic Issue Tra…
- CVE-2009-4351SQL injection vulnerability in ADMIN/loginaction.php in WSCr…
- CVE-2009-4352Multiple cross-site scripting (XSS) vulnerabilities in Trans…
- CVE-2009-4354TransWARE Active! mail 2003 build 2003.0139.0871 and earlier…
- CVE-2009-4355Memory leak in the zlib_stateful_finish function in crypto/c…
- CVE-2009-4356Multiple integer overflows in the jpeg.w5s and png.w5s filte…
- CVE-2009-4357CQWeb (aka the web interface) in IBM Rational ClearQuest bef…
- CVE-2009-4358freebsd-update in FreeBSD 8.0, 7.2, 7.1, 6.4, and 6.3 uses i…
- CVE-2009-4359Cross-site scripting (XSS) vulnerability in folder.php in th…
Are you affected by CVE-2009-4353?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
