CVE-2009-3657
Published Oct 9, 2009Session fixation vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack web sessions via unspecified vectors.
Vendor/product archive
2 CVEs tagged to tim_nelson / shared_sign-on — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
Session fixation vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack web sessions via unspecified vectors.
Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users via unk…