Security Advisory

CVE-2008-3222

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-07-18 16:00:00
Last updated 2024-08-07 09:28:41
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.