CVE-2013-7302
29.04.2014, 14:38
Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers after checkout" option is enabled, allows remote attackers to hijack web sessions by leveraging knowledge of the original session ID.Enginsight
Vendor | Product | Version |
---|---|---|
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.0:x |
ubercart | ubercart | 6.x-2.1:x |
ubercart | ubercart | 6.x-2.2:x |
ubercart | ubercart | 6.x-2.3:x |
ubercart | ubercart | 6.x-2.4:x |
ubercart | ubercart | 6.x-2.6:x |
ubercart | ubercart | 6.x-2.7:x |
ubercart | ubercart | 6.x-2.8:x |
ubercart | ubercart | 6.x-2.9:x |
ubercart | ubercart | 6.x-2.10:x |
ubercart | ubercart | 6.x-2.11:x |
ubercart | ubercart | 6.x-2.12:x |
ubercart | ubercart | 7.x-3.0:x |
ubercart | ubercart | 7.x-3.0:x |
ubercart | ubercart | 7.x-3.0:x |
ubercart | ubercart | 7.x-3.0:x |
ubercart | ubercart | 7.x-3.0:x |
ubercart | ubercart | 7.x-3.0:x |
ubercart | ubercart | 7.x-3.0:x |
ubercart | ubercart | 7.x-3.0:x |
ubercart | ubercart | 7.x-3.0:x |
ubercart | ubercart | 7.x-3.0:x |
ubercart | ubercart | 7.x-3.0:x |
ubercart | ubercart | 7.x-3.0:x |
ubercart | ubercart | 7.x-3.0:x |
ubercart | ubercart | 7.x-3.1:x |
ubercart | ubercart | 7.x-3.2:x |
ubercart | ubercart | 7.x-3.3:x |
ubercart | ubercart | 7.x-3.4:x |
ubercart | ubercart | 7.x-3.5:x |
𝑥
= Vulnerable software versions
Common Weakness Enumeration