{"id":"CVE-2016-4309","details":"Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter.","modified":"2026-07-08T12:53:12.596591Z","published":"2016-06-30T17:59:02.813Z","references":[{"type":"ADVISORY","url":"http://hyp3rlinx.altervista.org/advisories/SYMPHONY-CMS-SESSION-FIXATION.txt"},{"type":"ADVISORY","url":"http://www.securityfocus.com/archive/1/538714/100/0/threaded"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/91299"},{"type":"ADVISORY","url":"https://github.com/symphonycms/symphony-2/commit/b329a14adc40868965076a77210452e396243dcd"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/137551/Symphony-CMS-2.6.7-Session-Fixation.html"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/39983/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/symphonycms/symphonycms","events":[{"introduced":"1ff58f8c82c5da4900616647c4aa494e651fa6ec"},{"last_affected":"1ff58f8c82c5da4900616647c4aa494e651fa6ec"},{"fixed":"b329a14adc40868965076a77210452e396243dcd"}],"database_specific":{"cpe":"cpe:2.3:a:getsymphony:symphony:2.6.7:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.6.7"},{"last_affected":"2.6.7"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["2.6.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4309.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}