Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-3222

Опубликовано: 18 июл. 2008
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5.8

Описание

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

feisty

ignored

end of life, was needs-triage
gutsy

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

released

5.9

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

feisty

DNE

gutsy

ignored

end of life, was needs-triage
hardy

released

5.7-1ubuntu1.1
intrepid

not-affected

5.9-1ubuntu1
jaunty

not-affected

5.9-1ubuntu1
karmic

not-affected

5.9-1ubuntu1
upstream

released

5.9

Показывать по

EPSS

Процентиль: 77%
0.01059
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

nvd
почти 17 лет назад

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.

debian
почти 17 лет назад

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before ...

github
около 3 лет назад

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.

EPSS

Процентиль: 77%
0.01059
Низкий

5.8 Medium

CVSS2