6.8
CVSSv2

CVE-2014-9015

Published: 24/11/2014 Updated: 20/12/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Drupal 6.x prior to 6.34 and 7.x prior to 7.34 allows remote malicious users to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal

debian debian linux 7.0

Vendor Advisories

Debian Bug report logs - #770469 drupal7: CVE-2014-9015 CVE-2014-9016 (SA-CORE-2014-006) Package: src:drupal7; Maintainer for src:drupal7 is Gunnar Wolf <gwolf@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 21 Nov 2014 14:51:05 UTC Severity: serious Tags: fixed-upstream, security, upstr ...
Two vulnerabilities were discovered in Drupal, a fully-featured content management framework The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2014-9015 Aaron Averill discovered that a specially crafted request can give a user access to another user's session, allowing an attacker to hijack a random ...