Session Hijacking Vulnerability in Drupal by Acquia
CVE-2014-9015

Currently unrated

Key Information:

Vendor

Drupal

Status
Vendor
CVE Published:
24 November 2014

What is CVE-2014-9015?

A security vulnerability in Drupal versions prior to 6.34 and 7.34 enables remote attackers to hijack sessions through crafted HTTP requests, especially when both HTTP and HTTPS sessions are supported by the same server. This flaw could allow unauthorized access to user accounts, potentially compromising sensitive information and leading to further exploitation if left unpatched.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.