Back to search
CVE-2014-9015
Published: Nov 24, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20141120 Pending CVE assignments for SA-CORE-2014-006?
mailing-list
x_refsource_MLIST
https://www.drupal.org/SA-CORE-2014-006
x_refsource_CONFIRM
[oss-security] 20141120 Re: [security] Pending CVE assignments for SA-CORE-2014-006?
mailing-list
x_refsource_MLIST
59164
third-party-advisory
x_refsource_SECUNIA
59814
third-party-advisory
x_refsource_SECUNIA
DSA-3075
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now