CVE Vulnerabilities

CVE-2014-9015

Published: Nov 24, 2014 | Modified: Dec 20, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

Affected Software

Name Vendor Start Version End Version
Drupal Drupal 6.0 (including) 6.34 (excluding)
Drupal Drupal 7.0 (including) 7.34 (excluding)
Drupal6 Ubuntu lucid *
Drupal6 Ubuntu precise *
Drupal7 Ubuntu esm-infra-legacy/trusty *
Drupal7 Ubuntu precise *
Drupal7 Ubuntu trusty *
Drupal7 Ubuntu trusty/esm *
Drupal7 Ubuntu upstream *
Drupal7 Ubuntu utopic *

References