CVE Vulnerabilities

CVE-2006-1228

Improper Authentication

Published: Mar 14, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Drupal Drupal 4.5.0 (including) 4.5.0 (including)
Drupal Drupal 4.5.1 (including) 4.5.1 (including)
Drupal Drupal 4.5.2 (including) 4.5.2 (including)
Drupal Drupal 4.5.3 (including) 4.5.3 (including)
Drupal Drupal 4.6.0 (including) 4.6.0 (including)
Drupal Drupal 4.6.1 (including) 4.6.1 (including)

Potential Mitigations

References