Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-1228

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.022
EPSS Ranking 83.6%
CVSS Severity
CVSS v2 Score 5.1
Products affected by CVE-2006-1228
  • Drupal » Drupal » Version: 4.5.0
    cpe:2.3:a:drupal:drupal:4.5.0
  • Drupal » Drupal » Version: 4.5.1
    cpe:2.3:a:drupal:drupal:4.5.1
  • Drupal » Drupal » Version: 4.5.2
    cpe:2.3:a:drupal:drupal:4.5.2
  • Drupal » Drupal » Version: 4.5.3
    cpe:2.3:a:drupal:drupal:4.5.3
  • Drupal » Drupal » Version: 4.6.0
    cpe:2.3:a:drupal:drupal:4.6.0
  • Drupal » Drupal » Version: 4.6.1
    cpe:2.3:a:drupal:drupal:4.6.1


Contact Us

Shodan ® - All rights reserved