LWN.net Logo

drupal: session fixation

Package(s):drupal CVE #(s):
Created:August 1, 2008 Updated:August 6, 2008
Description: From this Drupal advisory: When contributed modules such as Workflow NG terminate the current request during a login event, user module is not able to regenerate the user's session. This may lead to a session fixation attack, when a malicious user is able to control another users' initial session ID. As the session is not regenerated, the malicious user may use the 'fixed' session ID after the victim authenticates and will have the same access.
Alerts:
Fedora FEDORA-2008-6916 2008-07-31

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds