Vulnerability Bulletins

SA-2008-046 - Drupal core - Session fixation

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-2008-046Project: Drupal coreVersion: 5.xDate: 2008-July-23Security risk: Less criticalExploitable from: RemoteVulnerability: Session fixationDescriptionWhen contributed modules such as Workflow NG terminate the current request during a login event, user module is not able to regenerate the users session. This may lead to a session fixation attack, when a malicious user is able to control another users initial session ID. As the session is not regenerated, the malicious

More info:

https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2008-07-23/sa-2008-046-drupal-core-session