Lucene search

K
cve[email protected]CVE-2008-3222
HistoryJul 18, 2008 - 4:41 p.m.

CVE-2008-3222

2008-07-1816:41:00
CWE-384
web.nvd.nist.gov
19
4
drupal
session fixation
vulnerability
remote attackers
web sessions

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.2 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.1%

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules “terminate the current request during a login event,” allows remote attackers to hijack web sessions via unknown vectors.

Affected configurations

NVD
Node
drupaldrupalRange5.05.9
OR
drupaldrupalRange6.06.3
Node
fedoraprojectfedoraMatch8
OR
fedoraprojectfedoraMatch9

Social References

More

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.2 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.1%