PT-2006-2244 · Drupal · Drupal

Markus Petrux

·

Published

2006-03-14

·

Updated

2018-10-18

·

CVE-2006-1228

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal versions 4.5.x through 4.5.7 Drupal versions 4.6.x through 4.6.7
Description A session fixation issue allows remote attackers to gain privileges by tricking a user into clicking on a URL that fixes the session identifier.
Recommendations For versions 4.5.x through 4.5.7, update to version 4.5.8 or later. For versions 4.6.x through 4.6.7, update to version 4.6.8 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-1228
DSA-1007-1

Affected Products

Drupal