Drupal Insecure Cookie Disclosure Weakness
BID:31285
Info
Drupal Insecure Cookie Disclosure Weakness
| Bugtraq ID: | 31285 |
| Class: | Design Error |
| CVE: |
CVE-2008-3661 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2008 12:00AM |
| Updated: | Oct 16 2008 01:57PM |
| Credit: | Hanno Boeck |
| Vulnerable: |
Red Hat Fedora 9 Red Hat Fedora 8 Drupal Drupal 6.4 Drupal Drupal 6.3 Drupal Drupal 6.2 Drupal Drupal 6.1 Drupal Drupal 6.0 Drupal Drupal 5.9 Drupal Drupal 5.8 Drupal Drupal 5.7 Drupal Drupal 5.6 Drupal Drupal 5.5 Drupal Drupal 5.4 Drupal Drupal 5.3 Drupal Drupal 5.2 Drupal Drupal 5.10 Drupal Drupal 5.1 Drupal Drupal 5.0 |
| Not Vulnerable: | |
Discussion
Drupal Insecure Cookie Disclosure Weakness
Drupal is prone to a cookie-disclosure weakness.
An attacker may leverage this issue to obtain sensitive information and steal cookie-based authentication credentials. This may aid in other attacks.
Drupal is prone to a cookie-disclosure weakness.
An attacker may leverage this issue to obtain sensitive information and steal cookie-based authentication credentials. This may aid in other attacks.
Exploit / POC
Drupal Insecure Cookie Disclosure Weakness
An attacker can exploit the issue by using readily available network sniffers.
An attacker can exploit the issue by using readily available network sniffers.
Solution / Fix
Drupal Insecure Cookie Disclosure Weakness
Solution:
Fixes are available. Please see the references for more information.
Solution:
Fixes are available. Please see the references for more information.
References
Drupal Insecure Cookie Disclosure Weakness
References:
References:
- Drupal Language Switcher Dropdown Homepage (Drupal)
- drupal: Session hijacking vulnerability, CVE-2008-3661 (Hanno Boeck)
- Hanno Boeck (drupal: Session hijacking vulnerability, CVE-2008-3661)