Project

General

Profile

Actions

Bug #19908

closed

session fixation fix avoid BE login

Added by Steffen Kamper over 15 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Must have
Assignee:
Category:
-
Target version:
-
Start date:
2009-01-25
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
4.3
PHP Version:
5.3
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

After the fixation fix i can't login in BE.
To be more precise:
Login works, but i'm logged out immediately and only get error bos with "Login-error or session timed-out"

If i comment the fixation check in class.t3lib_userauth.php, line 229, login works again.

(issue imported from #M10257)


Related issues 5 (0 open5 closed)

Related to TYPO3 Core - Bug #19831: Session fixation vulnerability in user authenticationClosedMarcus Krause2009-01-15

Actions
Related to TYPO3 Core - Bug #19912: The Bug 0010205 "DB session records are only created when users authenticate " is not solved in Typo 4.2.5 and 4.1.9ClosedHelmut Hummel2009-01-25

Actions
Related to TYPO3 Core - Bug #19879: after upgrade from 4.1.7 to 4.1.8 feusers and beusers have to clear there cookie cache before they can loginClosedHelmut Hummel2009-01-21

Actions
Related to TYPO3 Core - Bug #19916: Session handling - cannot login to >1 TYPO3 installation under one domainClosedMarcus Krause2009-01-26

Actions
Related to TYPO3 Core - Bug #20424: Built In shopping basket is not workingClosedBenni Mack2009-05-14

Actions
Actions

Also available in: Atom PDF