CVE-2008-3222
18.07.2008, 16:41
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.Enginsight
Vendor | Product | Version |
---|---|---|
drupal | drupal | 5.0 ≤ 𝑥 < 5.9 |
drupal | drupal | 6.0 ≤ 𝑥 < 6.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References